Also on CyberFence: compare CyberFence to other VPNs side-by-side · the free CyberFence security tools .
On September 22, 2026, Microsoft announced it had disrupted EvilTokens, a subscription-based cybercrime platform that used AI at every stage of its attacks — from crafting the phishing lure to deciding which employee at a company was most likely to approve a fraudulent payment. Working with its Digital Crimes Unit, Health-ISAC, Cloudflare, Coinbase, OpenAI, and several other partners, Microsoft obtained a federal court order to seize 50 websites and disable more than 150 additional domains tied to the operation. UK police arrested two men suspected of running it (Microsoft, SecurityWeek).
This is one of the more consequential cybercrime disruptions of 2026, and it is worth understanding — not because EvilTokens is gone (it isn't, entirely), but because the attack method it popularized is now widely copied and will keep showing up in inboxes for a long time.
What EvilTokens Actually Did
EvilTokens launched in February 2026 and was sold through a Telegram channel for a $1,500 setup fee plus $500 a month — a price point that put a sophisticated attack kit within reach of almost any criminal, not just skilled hackers. In a matter of months, Microsoft says it was linked to more than 12,000 compromised email inboxes across over 10,000 organizations worldwide, with the heaviest concentration of victims in the United States (CyberScoop, The Hacker News).
The technique behind it is called device-code phishing, and it is specifically designed to get around multi-factor authentication rather than through it. Microsoft accounts support a legitimate sign-in method called the OAuth 2.0 device authorization flow, originally built for devices without a keyboard — think smart TVs or conference-room hardware. A user is shown a short code and asked to enter it on a second device to approve the sign-in.
EvilTokens weaponized this. Victims received a message — often appearing to come from a colleague or a trusted service, frequently via Teams or email — asking them to visit a legitimate Microsoft sign-in page and enter a code to "verify" a meeting invite, a document share, or an account issue. The code was real. The sign-in page was real. But entering that code handed the attacker a valid, authenticated session token for the victim's account — no password guessed, no MFA prompt bypassed, because the victim approved it themselves (Dark Reading).
Once inside an inbox, the platform's AI component took over. According to Microsoft, it analyzed the compromised mailbox to map trusted relationships, identify who controlled payments inside the organization, and flag where financial fraud was most likely to succeed — turning a single stolen session into a targeted business email compromise (BEC) campaign aimed at vendors, clients, or finance staff (Fortune).
Phishing links don't check your password — they check whether you'll click. CyberFence's Web Shield blocks known malicious and phishing domains at the DNS level, before the page ever loads.
See CyberFence Plans →Why the Takedown Doesn't End the Threat
Microsoft's disruption removed a large chunk of EvilTokens' infrastructure — the 50 websites used to run the service and 150-plus supporting domains — and Coinbase traced roughly $1.1 million in subscription revenue through blockchain analysis to help build the case (Fortune/Startup Fortune). Two suspects were arrested in London. But security researchers are clear that this was a disruption, not a full takedown: device-code phishing as a technique isn't going anywhere, and copycat kits using the same approach are already active (BleepingComputer).
That matters because the underlying lesson isn't really about EvilTokens specifically. It's about a shift already well underway in phishing: attackers no longer need to steal a password when they can convince you to hand over an already-authenticated session instead. And AI tools now do the tedious part of that job — writing the lure, picking the target, and figuring out the fraud angle — for a monthly subscription fee anyone can afford.
What Actually Stops This Kind of Attack
It's worth being precise about what does and doesn't help here, because not every security tool is built for this threat.
- A VPN's encryption doesn't stop device-code phishing. This attack doesn't rely on intercepting your traffic on the network — it relies on a message reaching your inbox and you approving a login. Encrypting the connection between your device and the internet doesn't change whether that message gets through or whether you click it.
- DNS-level phishing blocking is the relevant defense. CyberFence's Web Shield checks every outbound connection against a list of known malicious and phishing domains and blocks the connection before the page loads — before you ever see the fake sign-in screen or the "verify your code" prompt. If the phishing link routes through a domain already flagged as malicious, Web Shield stops it at the DNS layer, regardless of how convincing the message looks.
- Breach Monitor tells you if you're already exposed. If your email address or credentials show up in a known breach or dark web dataset — which is exactly what happens after an inbox compromise like this — Breach Monitor alerts you so you can act before the exposure is used against you.
- Slow down on any "enter this code" request. No legitimate colleague, vendor, or IT department needs you to type a verification code into a sign-in page to approve a meeting, document, or account check. If a message asks for that, treat it the same way you'd treat someone asking for your password directly.
Why Small Businesses Are Exactly the Target
The 10,000-plus organizations affected by EvilTokens weren't concentrated among giant enterprises with dedicated security teams. A $500-a-month subscription price point was specifically low enough for a criminal to profitably target ordinary companies — the kind where one compromised inbox in accounting or operations is enough to redirect a vendor payment or a payroll transfer. If your business doesn't have a way to know whether every employee's device is actually protected against phishing domains, or whether a compromised account has already leaked credentials elsewhere, you're relying entirely on people noticing something is off — and this generation of phishing kits is built specifically to make sure they don't.
CyberFence Teams gives a business owner visibility that an individual VPN subscription per employee never provides: a real-time admin dashboard showing which team members actually have protection active, non-adoption alerts when someone doesn't, and Breach Monitor coverage across every seat — all for $12 per seat per month with no contract.
Don't find out about a compromised inbox from a client. CyberFence protects every device your team uses with AES-256-GCM encryption, Web Shield phishing blocking, and Breach Monitor — with one dashboard showing exactly who's covered.
Get Protected →If You Think You Approved a Fake Code
Device-code phishing is effective precisely because approving the code feels routine — most people don't realize anything happened until money moves or a colleague asks why they got a strange email. If you suspect you entered a verification code for something you didn't fully recognize, a few steps matter more than others:
- Sign out of all active sessions on the account in question, not just the device you're using. Most major email providers have a security setting that revokes every active session at once.
- Check for new mailbox rules or forwarding addresses. A common follow-on move after this kind of compromise is a quiet forwarding rule that copies certain messages — often anything mentioning invoices or payments — to an external address.
- Change your password even if MFA is enabled. The session token an attacker gains through device-code phishing can outlast a password change in some cases, which is exactly why revoking sessions matters as much as the password itself.
- Tell your finance or accounts-payable contacts directly — by phone, not email — if there's any chance a compromised inbox could be used to redirect a payment. Business email compromise attacks depend on nobody double-checking a request that looks like it came from the usual person.
The Bottom Line
EvilTokens is the latest reminder that phishing has moved past the era of obvious red flags. The messages are AI-written, the sign-in pages are real, and the target selection is automated. Microsoft's takedown removed a major piece of that infrastructure, but the technique it used — and the AI tooling that made it scale — will keep showing up under new names.
The defense that actually matters here isn't a stronger password or a longer MFA code. It's blocking the malicious domain before the page loads, and knowing immediately if your credentials have already been exposed. That's what DNS-level phishing protection and breach monitoring are built to do — and it's worth having both running on every device you use to check email, not just the one on your desk.
Want to go deeper? Read the CyberFence competitor comparison hub , our free privacy and security tools , or CyberFence plans and pricing .