
What was reported
Microsoft's EvilTokens report describes abuse of device-code authentication and subsequent mailbox compromise. The researchers associate the service with Storm-2992 and report a coordinated disruption with partners. The publication covers activity observed over time; it does not establish that every organization received the same campaign.
Defensive perspective
An authentication code should only be entered for a sign-in the user intentionally started. Organizations should review where device-code authentication is needed, apply suitable access policies and investigate unusual consent or mailbox activity. Multifactor authentication does not remove the need to validate the authentication request itself.
Forensic focus
Preserve the original lure, identity sign-in records and mailbox audit records. Examine unexpected inbox rules and device registrations in context. Follow the organization's incident process for session revocation and account recovery, recording the timing of each response action so it can be distinguished from attacker activity.
Source published 22 September 2026. Briefing prepared 26 September 2026.