← NEWS & INSIGHTS

NEWS / RESEARCH & ANALYSIS

EvilTokens research puts device-code phishing under the microscope

Microsoft documents token-focused phishing and explains why a familiar sign-in page does not make an unsolicited authentication request safe.

Source published 2026-09-22IdentityPhishingEmail security
Original publication preview: EvilTokens research puts device-code phishing under the microscope
Microsoft Security ↗

What was reported

Microsoft's EvilTokens report describes abuse of device-code authentication and subsequent mailbox compromise. The researchers associate the service with Storm-2992 and report a coordinated disruption with partners. The publication covers activity observed over time; it does not establish that every organization received the same campaign.

Defensive perspective

An authentication code should only be entered for a sign-in the user intentionally started. Organizations should review where device-code authentication is needed, apply suitable access policies and investigate unusual consent or mailbox activity. Multifactor authentication does not remove the need to validate the authentication request itself.

Forensic focus

Preserve the original lure, identity sign-in records and mailbox audit records. Examine unexpected inbox rules and device registrations in context. Follow the organization's incident process for session revocation and account recovery, recording the timing of each response action so it can be distinguished from attacker activity.

Source published 22 September 2026. Briefing prepared 26 September 2026.

Read Microsoft's report.

Search the lab

NEWS / FORENSICS / FIELD GUIDES ESC