The coordinated effort combined legal action by Microsoft’s Digital Crimes Unit and technical takedowns by Cloudflare, effectively neutralising the phishing‑as‑a‑service (PhaaS) operation that sold access to a web‑based panel for stealing Microsoft Office 365 authentication tokens.

EvilTokens, which first surfaced on Telegram, offered customers an automated system that harvested session tokens, allowing attackers to retain access to compromised mailboxes even after the original tokens expired. The service also bundled an AI‑driven coach that helped users craft phishing lures tied to U.S. tax documents, invoices and accounting correspondence, signalling a shift toward packaged tools and guidance for less‑experienced cybercriminals.

According to Cloudflare’s threat‑intelligence team, Cloudforce One, the platform was linked to more than 12,000 compromised inboxes in over 10,000 organisations, with Australia recording one of the highest concentrations of victim activity.

Microsoft pursued a civil action in the United States to gain control of the domains used by EvilTokens, while Cloudflare identified and disabled hundreds of related domains, Cloudflare Worker projects and accounts. For domains that could not be seized due to jurisdictional limits, warning pages were deployed to block access to the phishing content.

Investigators noted that a third‑party entity, based in another country, purchased and configured the domains for EvilTokens and other scams, suggesting a broader support network behind the operation. The service’s abuse of Cloudflare infrastructure allowed users to bring their own API keys to configure Workers that collected credentials and routed stolen data to Telegram channels.

The disruption highlights the financial risk of business email compromise (BEC), which exploits legitimate corporate mailboxes to request fraudulent payments or extract sensitive information. By stealing valid session tokens, attackers can bypass multi‑factor authentication (MFA) without needing the second factor again.

Cloudflare urged organisations to adopt phishing‑resistant authentication methods such as FIDO2, WebAuthn, hardware security keys and passkeys, and to tighten conditional‑access controls, limit logins to managed devices, monitor impossible‑travel patterns, and enforce stricter DMARC, SPF and DKIM policies.