Incident
Published 2026-09-22
Verified 2026-09-27

Microsoft DCU disrupts EvilTokens AI PhaaS (Storm-2992): 12,000+ inboxes / 10,000+ orgs; AU among top victim countries

Microsoft On the Issues / Digital Crimes Unit (22 September 2026) and Microsoft Threat Intelligence (“Unmasking EvilTokens”) detail disruption of EvilTokens, a phishing-as-a-service platform Microsoft tracks as Storm-2992. The service abused OAuth 2.0 device-code authentication against Microsoft’s legitimate sign-in flow (MFA-bypass style session/token theft without password capture) and centred an AI-style chatbot that analysed compromised mailboxes to pick BEC targets, impersonation paths, and fraud plays. Microsoft links >12,000 compromised inboxes across >10,000 organisations since the Feb 2026 launch; highest victim concentrations include the United States, Canada, the United Kingdom, Australia, India, and France. Partners helped seize ~50 operator sites and disable 150+ related domains; UK Metropolitan Police arrested two suspected administrators. Sold via Telegram (~US$1,500 init + US$500/month). Primary: Microsoft On the Issues; TI: aka.ms/EvilTokens-PhaaS; wire: BleepingComputer 22 Sep 2026.

Product
EvilTokens PhaaS / Storm-2992 (device-code phishing vs Microsoft identity); Microsoft 365 / Entra ID tenants
Exploited in Australia?
unknown
Patch to
Disable or tightly control device-code / device-authorization grant where unused; require phishing-resistant MFA/passkeys; revoke refresh tokens and sign-out sessions after suspected device-code phishing; hunt for unusual device-code consent and BEC follow-on; review Microsoft TI mitigations (aka.ms/EvilTokens-PhaaS)

Primary: Microsoft On the Issues — Disrupting EvilTokens (22 Sep 2026) · Vendor: Microsoft Threat Intelligence — Unmasking EvilTokens / device-code phishing · BleepingComputer — EvilTokens PhaaS disrupted (22 Sep 2026)

ai identity australia