738 S 9th St, Philadelphia, PA 19147Call/text 215 821-9605
All news
Cybersecurity

EvilTokens Disrupted: Why a Password Reset May Not End an Account Takeover

Microsoft and partners disrupted an AI-assisted phishing service tied to thousands of inboxes. Customers should understand why stolen sessions can survive a password change.

September 23, 2026 4 min read
EvilTokens Disrupted: Why a Password Reset May Not End an Account Takeover

Microsoft and several partners announced on September 22 that they had disrupted EvilTokens, a phishing-as-a-service platform built to compromise Microsoft 365 accounts and help criminals prepare financial fraud. Microsoft says the service was linked to more than 12,000 compromised inboxes across more than 10,000 organizations after appearing in February 2026. Cloudflare separately confirmed that its Cloudforce One team participated in the legal and technical operation against infrastructure used by the service. Two men were also arrested in the United Kingdom in connection with the alleged operation; the investigation remains ongoing, so those arrests should not be treated as convictions.

The most useful lesson for everyday customers is how the attack worked. Victims could be sent to Microsoft's legitimate device-login page and persuaded to enter a code created by an attacker. That action authorized the attacker's session without revealing the victim's password. Once inside, EvilTokens could use AI-assisted tools to search email, identify trusted contacts, study invoice or payment discussions, and help prepare convincing impersonation messages. Microsoft reports that stolen access could persist through tokens, registered devices, or malicious inbox rules. That means changing a password is important, but it may not remove every path the attacker created.

If you entered an unexpected device code, approved a sign-in you did not start, or see unfamiliar sent mail or forwarding rules, act quickly. Change the password from a trusted device, sign out active sessions, revoke suspicious app consent and authentication tokens, remove unfamiliar registered devices, inspect inbox and forwarding rules, and contact the organization's administrator. Businesses should restrict device-code authentication where it is not needed, require phishing-resistant sign-in methods for sensitive accounts, and independently confirm payment changes through a known phone number or another trusted channel.

Orange Tech's interpretation is straightforward: modern phishing can abuse a real sign-in screen, so a familiar web address is not enough proof that a request is safe. Never enter a device code unless you personally initiated the setup on a device you control. For money transfers, vendor-bank changes, or urgent executive requests, pause and verify with a person before acting.