# Microsoft-led operation disrupts phishing service tied to 12,000 accounts

_Published Tuesday, September 22, 2026 at 12:09 PM EDT · Security · Latest · Tier 1 — Major_

![Microsoft-led operation disrupts phishing service tied to 12,000 accounts — Primary](https://www.bleepstatic.com/content/hl-images/2026/09/22/phishing.jpg)

Microsoft and partners disrupted infrastructure used by EvilTokens, a phishing-as-a-service operation linked to more than 12,000 compromised Microsoft inboxes across over 10,000 organizations. British police arrested two suspected administrators, who were released on bail pending further investigation.

EvilTokens abused Microsoft's device-code authentication flow to obtain access tokens despite multifactor authentication, then used Microsoft Graph and AI tools to identify valuable messages and targets. The operation seized active infrastructure under legal authority, but Microsoft characterized it as a disruption rather than a complete takedown; the threat remains active and clones have appeared.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/eviltokens-phaas-disrupted-after-compromising-12-000-microsoft-accounts/)

---
Canonical: https://techandbusiness.org/newswire/utOxfo2BKbWJvwiN-xmuUs
Published: 2026-09-22T16:09:21.870Z
Story chronology: 2026-09-22T15:00:00.000Z
Retrieved: 2026-09-22T17:43:28.959Z
Publisher: Tech & Business (techandbusiness.org)
