How AI Phishing Kits Bypass MFA on Microsoft Accounts

Microsoft disrupted EvilTokens, a subscription phishing service that used a chatbot to read stolen inboxes and pick payment targets. Here is how it got past MFA and what to change this month.

Microsoft said it led an industry-wide takedown of a paid phishing service called EvilTokens, which was used to compromise 12,000 accounts across 10,000 organizations, as reported by Ars Technica. The part that should interest business owners is not the volume. It is the method: the attackers did not crack passwords or steal one-time codes, and once inside an inbox, an AI chatbot did the reconnaissance work that used to take a human days.

What actually changed

EvilTokens was sold like software. It appeared on a Telegram channel in February, cost $1,500 to start and $500 a month after that, and packaged most of the steps of a mass email compromise into one dashboard.

The entry point was device code authentication. That is a legitimate OAuth flow built for televisions and other devices that cannot easily handle a login form: the device shows a short code, you type it into a browser on your phone or laptop, and the device gets signed in. EvilTokens sent bulk spam; victims who clicked a link landed on a page running a hidden script that talked to the Microsoft identity provider in real time and generated a device code for a device the attacker controlled. The victim was then shown that code with instructions to enter it on the official Microsoft device login page. Because the login page is genuine and the victim completes the sign-in themselves, this consent-style flow does not look like a stolen password.

After access, the chatbot took over. Microsoft said the platform could analyze a victim's inbox to find trusted relationships, who holds payment authority, and where fraud was most likely to work, then draft messages impersonating known contacts. It processed 5,000 compromised mailboxes at a time and mapped out which employees could move money and which managers they report to.

Victims were concentrated in the US, followed by Canada, the UK, Australia, India and France, across wholesale distribution, construction, financial services, real estate, higher education and healthcare. Microsoft seized 50 websites and 150 further domains through a legal process, and the UK's Metropolitan Police Service arrested two men on suspicion of related offenses.

Why it matters for a small business

Two assumptions that many small companies rely on just got weaker.

The first is that multi-factor authentication is the finish line. Here MFA was not defeated by phishing a code out of someone. The victim was walked through a real Microsoft sign-in that enrolled the attacker's device. If your security story is "we turned on MFA," that story now has a gap.

The second is that a break-in buys you time. Microsoft's own summary of the lesson is direct: assume that once an inbox is compromised, criminals can understand its contents in minutes rather than days. The old comfort — that an attacker has to read thousands of emails before they know who signs off on payments — is gone. A ten-person company with one bookkeeper and one director is a very small graph for a model to map.

This matters most anywhere payment details travel by email: supplier invoices, bank account changes, deposit instructions to clients. That is nearly every small business with outside vendors.

What to do about it

  • Ask whoever administers your Microsoft or Google workspace to restrict or block device code sign-in for staff who never use it. Almost no office worker needs it on a laptop or phone.
  • Write a second-channel rule and make it boring: any request to change bank details, redirect a payment or approve an unusual transfer is confirmed by a phone call to a number you already had on file, never a number from the email.
  • Review connected apps and enrolled devices in your admin console. Remove anything you do not recognize, and set a date to do it again next quarter.
  • Tell your team what this specific trick looks like: a page that hands you a code and tells you to enter it on a real Microsoft login screen. Legitimate work logins rarely ask for that.
  • Check that sign-in logs and mailbox rule changes are actually being monitored by someone. Attackers who get in tend to add forwarding rules early.

The technical defense here is one admin setting and a habit. The organizational defense is deciding, in advance, that no payment instruction is ever confirmed inside the same channel it arrived in. Neither costs much. Both are worth doing before someone in your finance inbox receives a very convincing message from a supplier you have worked with for years.

SourceWritten from reporting by Ars Technica. Read the original: Microsoft disrupts AI-assisted platform that compromised 12,000 accounts

More articlesAll articles