Microsoft and Cloudflare have disrupted EvilTokens, a cybercrime service used to break into Microsoft 365 email accounts and help criminals carry out payment fraud.
The operation targeted the websites, domains, and Cloudflare tools that EvilTokens and its customers used to run phishing campaigns. Microsoft said the service was linked to more than 12,000 compromised inboxes across over 10,000 organizations worldwide
For businesses, the danger went beyond a stolen email account. Once inside an inbox, criminals could read conversations with suppliers and colleagues, then impersonate someone the victim trusted. A fake message changing bank details on an invoice, for example, could send a legitimate payment to a criminal instead.
EvilTokens sold access to an online control panel that helped its customers collect authentication tokens. These tokens are digital proof that a user has signed in. If stolen, they can give a criminal access to an account even when the owner uses multifactor authentication. Microsoft said some access could remain after a password reset unless the affected sessions and tokens were also revoked
The service also offered AI tools to help criminals examine stolen inboxes, find payment discussions, and draft convincing messages. Its panel included an AI coach covering topics such as invoices and business email fraud.
EvilTokens customers could use their own Cloudflare accounts to set up phishing pages. The kit used Cloudflare Workers, a tool for running code online, to collect information entered by victims. Cloudflare said its Cloudforce One threat research team identified hundreds of accounts tied to the operation and removed associated domains and Workers projects.
The Sept. 15 operation combined Cloudflare’s technical action with a civil case brought by Microsoft’s Digital Crimes Unit. Microsoft said it and its partners seized 50 websites and disabled more than 150 additional domains supporting EvilTokens. Cloudflare also placed warning pages in front of phishing links it could not remove through the domain seizure process
The takedown interrupts one service, but affected businesses still need to secure compromised accounts. Microsoft advised organizations to verify unusual payment requests through a separate, trusted channel. Where an account has been breached, changing its password alone may not end a criminal’s access; its active sessions and tokens must also be revoked.