
EvilTokens infrastructure disrupted; Microsoft reports 12,000-plus compromised inboxes
Microsoft says it worked with partners to disrupt EvilTokens infrastructure. Its research links the service to BEC campaigns that compromised more than 12,000 inboxes at over 10,000 organizations.
According to research published by Microsoft on September 22, 2026, EvilTokens facilitated business email compromise (BEC) campaigns that compromised more than 12,000 inboxes at over 10,000 organizations worldwide. These are Microsoft's research findings, not independently verified exact victim totals.
The disruption did not eliminate the threat
Microsoft's Digital Crimes Unit (DCU) said it worked with partners to disrupt infrastructure used to operate EvilTokens. BleepingComputer reported that the effort stopped short of a full takedown and that the threat remains active.
According to BleepingComputer, two suspects were arrested in the United Kingdom as part of the EvilTokens investigation. The Record reported that both were later released on bail while the police investigation continues.
How the device code flow is abused
Microsoft says attackers using EvilTokens can abuse the legitimate device code authentication flow. An attacker initiates the flow and sends a code to the user through a phishing lure. If the user enters the code, they may unknowingly authorize the attacker's session, giving the attacker access to the account without exposing the password.
A separate dataset uses a different measure
The SpyCloud dataset cited by BleepingComputer shows more than 8,708 compromised accounts across 6,585 corporate email domains in 79 countries. Its scope and unit of measurement differ from Microsoft's inbox tally, so it should not be treated as independent confirmation of the 12,000-plus figure.
Microsoft's device code flow recommendations
Microsoft recommends blocking device code flow wherever possible. For Teams devices that require the flow, the company advises restricting the exception to specific Teams device resource accounts and excluding the Device Registration Service resource from the relevant Conditional Access policy.

