
Microsoft says it has led an industry-wide takedown of EvilTokens, a subscription phishing service that compromised around 12,000 Microsoft accounts over a few months. The action was authorised by a US federal court and involved partners including Cloudflare, Coinbase and OpenAI.
How it worked
EvilTokens was sold on Telegram from February, for an upfront fee of US$1,500 plus US$500 a month. Customers got a ready-made kit for breaking into email accounts in bulk, using a technique called device code phishing. The victim is sent to a genuine Microsoft sign-in page and asked to enter a short code. Typing that code in quietly hands the criminal access to the mailbox, and because the page is real, it looks entirely normal.
According to reporting on Microsoft’s findings, the platform then used AI to read through stolen inboxes, pick out the targets likely to pay the most, and draft convincing follow-up emails designed to get staff to transfer money to accounts the criminals control.
Why this matters to a small business
This one service has been shut down, but the technique has not gone away. Fake invoices and changed bank details sent from a real, trusted inbox are among the most costly scams a small business can fall for. The money often cannot be recovered.
Three practical steps
- Never enter a sign-in code you did not ask for. If an email, message or caller asks you to type a code into a Microsoft page, stop and check with your IT provider first.
- Confirm any change to payment details by phone, using a number you already have, not one in the email.
- Ask your IT provider whether code-based sign-in can be switched off for your Microsoft 365. Most businesses never use it, and turning it off closes this door entirely.
Worried this affects your business? Get a free 15-minute IT check – call Trends IT on 0485 011 911 or visit /contact/.
