Microsoft Shuts Down EvilTokens Phishing Platform Targeting Office 365

Microsoft has taken down a phishing-as-a-service operation known as EvilTokens, seizing 50 websites and disabling over 150 domains. The service was used to compromise Microsoft 365 accounts through device code phishing attacks. The disruption is part of a coordinated effort to curb credential theft.
Microsoft’s takedown of EvilTokens marks a significant blow to a credential-theft service that specifically targeted Microsoft 365 users. By seizing 50 websites and disabling more than 150 domains, the operation disrupted a phishing-as-a-service model that enabled attackers to deploy device code phishing—a technique that tricks users into approving sign-in requests on compromised devices. This coordinated action reduces the immediate availability of a widely used tool for account compromise.
The move underscores the growing threat of commoditized phishing, where malicious infrastructure is rented or sold rather than built by individual hackers. Such services lower the barrier for cybercriminals, making credential theft more accessible. Microsoft’s intervention likely forces operators to rebuild or relocate, but similar platforms may emerge, highlighting the ongoing need for vigilance against account takeover attempts.
The shutdown could reduce near-term phishing attacks against businesses and individuals relying on Microsoft 365, lowering the risk of data breaches and ransomware entry points. However, attackers may adapt by shifting to other platforms or reviving the service under new names. Organizations may need to reinforce multi-factor authentication and user training, as device code phishing exploits legitimate sign-in flows. The broader impact could be a temporary dip in credential theft, but long-term security depends on continued industry collaboration and user awareness.