Briefing

EvilTokens Phishing-as-a-Service Compromises 340 Microsoft 365 Organizations in Five Weeks

security
by [email protected] (The Hacker News) ·

Patch your MFA flow to reject device login requests that contain short codes and verify the request source.

What to do now

Patch your MFA verification to reject device login requests that contain short codes and verify the request source.

Summary

EvilTokens launched in February 2026 as a phishing‑as‑a‑service platform that quickly targeted Microsoft 365 tenants. Within five weeks it compromised more than 340 organizations across five countries, exploiting the device‑login flow. Victims received a message asking them to enter a short code at microsoft.com/devicelogin and then complete the normal MFA challenge. After the challenge, they were led to believe the verification succeeded and walked away. The attack leveraged the short‑code entry to bypass MFA checks, demonstrating a critical weakness in the device‑login verification process.

The incident underscores the need for stricter MFA validation and highlights how phishing‑as‑a‑service platforms can weaponise legitimate authentication flows. It also shows that even well‑known services like Microsoft 365 can be compromised through social engineering and subtle protocol abuse.

Key changes

  • EvilTokens launched in February 2026 as a phishing‑as‑a‑service platform
  • Within five weeks it compromised more than 340 Microsoft 365 organizations
  • The attack targeted five countries
  • Victims received a message asking to enter a short code at microsoft.com/devicelogin
  • They completed the normal MFA challenge and were led to believe verification succeeded
  • The platform leveraged device login code flow to bypass MFA

Affects

internal

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting