Follow the latest coverage, related explainers and connected technology stories.
Microsoft revealed that the phishing-as-a-service platform EvilTokens enabled AI-supported attacks and affected more than 12,000 mailboxes across more than 10,000 organizations. The platform was used to exploit the device code authentication flow and steal access tokens, before Microsoft’s Digital Crimes Unit coordinated an operation to disrupt the infrastructure associated with it.
Microsoft Security Research observed a series of intrusions that begin with calls and messages impersonating IT support, then exploit AiTM or device code flows to add an attacker-controlled MFA method, explore Microsoft Graph, and extract SharePoint, OneDrive, and email data. Microsoft says the activity has been ongoing since May 2026 and aims to turn temporary identity compromise into persistent cloud access.