Cybersecuritynews iconCybersecuritynewsSep 23, 2026

The Phishing Kit That Turned Microsoft’s Login Flow Into an AI-Powered Fraud Machine

EvilTokens turns a Microsoft sign-in into a route to corporate email fraud. The phishing kit, first seen in February 2026, tricks people into approving an attacker's login through a real device code process without handing over a password.

The Phishing Kit That Turned Microsoft’s Login Flow Into an AI-Powered Fraud Machine

Share this story

Send the public story page.

Useful takeaways from this story.

EvilTokens turns a Microsoft sign-in into a route to corporate email fraud.

The phishing kit, first seen in February 2026, tricks people into approving an attacker's login through a real device code process without handing over a password.

The lure usually arrives as an urgent email about an invoice, shared file, document signature or expiring […]

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

EvilTokens turns a Microsoft sign-in into a route to corporate email fraud. The phishing kit, first seen in February 2026, tricks people into approving an attacker's login through a real device code process without handing over a password. The lure usually arrives as an urgent email about an invoice, shared file, document signature or expiring […]

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app