Microsoft Digital Crimes Unit EvilTokens graphic with Microsoft logo; title overlay Microsoft Disrupts EvilTokens, 12,000+ inboxes and 10,000+ organizations

Microsoft’s Digital Crimes Unit said this week it disrupted EvilTokens, a paid phishing service that helped criminals take over more than 12,000 Microsoft email accounts at more than 10,000 organizations.

The platform launched on Telegram in February 2026. Operators sold access for about $1,500 up front and $500 a month. Microsoft said the United States had the highest concentration of victim activity, and that hit organizations included construction, wholesale distribution, financial services, real estate, higher education, and healthcare—sectors common across Texas.

EvilTokens did not need a stolen password. Victims were steered into completing a real Microsoft sign-in meant for devices without a keyboard. Attackers received session tokens, then used an AI assistant to scan the inbox for payment threads, reporting lines, and people worth impersonating. Password resets alone do not close that door if tokens and sessions stay live.

Acting on an order from the U.S. District Court for the Eastern District of Virginia, Microsoft and Health-ISAC seized 50 websites and disabled more than 150 related domains, with help from firms including Cloudflare, Coinbase, OpenAI, and SpyCloud. U.K. police arrested two men on suspicion of offenses tied to the service; both were released on bail. That is an investigation, not a closed case.

Texas companies should treat this as a disruption, not a cure. Copycat kits were already on the market, and construction-bid, invoice, and “document ready” lures map cleanly onto energy contractors, healthcare systems, developers, and distributors across the state.

Practical steps for a Microsoft 365 tenant:

  • Restrict or block the device-code sign-in flow in Microsoft Entra ID if the business does not need it for conference-room or kiosk hardware.
  • Prefer phishing-resistant multifactor authentication and Conditional Access that challenges unusual device and location patterns.
  • After any suspected compromise, revoke refresh tokens and active sessions—do not stop at a password change.
  • Require a second channel before any vendor-bank, payroll, or wire-instruction change. Finance and accounts-payable staff are the intended audience for this fraud.
  • Watch for new inbox rules, forwarding, and sudden “CEO asked me to pay this” mail.

Microsoft notified affected customers. If your tenant was not on that list, assume clones will keep testing the same gap. A Texas company that holds sensitive personal data also has notice clocks under state law if a breach later involves residents; confirm those timelines with counsel, not a blog post.

The marketplace for inbox theft just lost one storefront. The demand did not.

My I.T. Consultants is a managed service provider in Athens, TX. If you want the device-code and token settings on your Mabank company's Microsoft 365 tenant checked against this week’s EvilTokens disruption, call 903-675-5431, Monday through Friday, 7:00 a.m. to 6:00 p.m. A Free Assessment is the practical next step.


Need this handled for your team?

Free Assessment

My I.T. Consultants are Experts in the IT Industry

Certifications and Affiliations