Industry NewsAI Business & Ecosystem

Cloudflare and Microsoft dismantle EvilTokens phishing-as-a-service operation

By Ash Kate
Cloudflare and Microsoft dismantle EvilTokens phishing-as-a-service operation

Article content

Cloudflare and Microsoft have taken coordinated action against EvilTokens, a phishing-as-a-service platform designed to bypass multi-factor authentication and help criminals gain persistent access to Microsoft Office 365 environments.

Cloudflare's Cloudforce One threat research team worked with Microsoft's Digital Crimes Unit and other industry and law enforcement partners on the September 2026 disruption. Cloudflare carried out a technical takedown of infrastructure supporting EvilTokens, while Microsoft initiated a civil legal process to seize associated domains.

The operation highlights how cybercriminals are increasingly turning sophisticated security bypass techniques and AI-assisted tooling into packaged services that can be used by less technically capable attackers.

EvilTokens turns MFA bypass into a service

EvilTokens emerged on Telegram in January 2026, offering criminal customers access to a web-based panel that automated the collection of authentication tokens used to access Microsoft Office 365 environments.

The platform was designed to collect credentials and authentication tokens and enable persistent access even after a session token expired.

Cloudflare says EvilTokens became one of the more popular phishing-as-a-service kits used to bypass MFA and support Business Email Compromise campaigns. The operation caused financial losses and affected thousands of users globally.

The model effectively turned elements of an otherwise technically complex attack into an accessible service for criminal customers.

An AI coach for phishing campaigns

One of the more notable features of EvilTokens was its use of an AI coach.

According to Cloudflare, the platform provided guidance to its criminal users on subjects including US tax documents, Business Email Compromise and typical invoice and accounting correspondence.

The AI component was designed to help users develop more convincing phishing lures and social-engineering material, lowering the expertise required to run targeted campaigns.

This adds another dimension to the growing security challenge around generative AI. The technology is not only being incorporated into legitimate security and productivity tools, but is also being integrated into criminal platforms to help automate parts of the attack process.

Cloudflare executes technical takedown

Cloudforce One joined Microsoft in the coordinated disruption operation on September 15, 2026.

Cloudflare's investigation identified the broader domain infrastructure and hundreds of Cloudflare accounts associated with EvilTokens customers.

The company subsequently banned hundreds of domains and Cloudflare Workers projects connected to the operation and developed detection methods to prevent the malicious Worker scripts from being deployed.

Where domains could not be legally seized because of jurisdictional limitations, Cloudflare deployed warning pages designed to block users attempting to access known EvilTokens phishing infrastructure.

Microsoft pursues legal action

The disruption also involved a legal component led by Microsoft's Digital Crimes Unit.

Microsoft filed a civil action in a US court seeking to compel international domain registrars to suspend malicious domains and transfer control of those domains to Microsoft's Digital Crimes Unit.

The seized domains are being redirected to a disruption notice identifying the participating organisations.

The combined approach illustrates how cybersecurity companies and technology providers are increasingly using both technical controls and legal mechanisms to disrupt cybercrime infrastructure.

Why the operation matters for Microsoft 365 security

EvilTokens demonstrates why MFA alone cannot be treated as the end point of identity security.

Phishing kits capable of stealing authentication tokens can potentially allow attackers to operate within legitimate sessions rather than simply relying on stolen passwords.

Cloudflare recommends moving toward phishing-resistant authentication methods such as FIDO2, WebAuthn and passkeys, alongside stronger conditional access, managed-device requirements and controls designed to protect session integrity.

The company also recommends measures including DNS filtering, AI-driven email security, sandboxing and stronger DMARC, SPF and DKIM policies.

Australia and the broader regional threat

The EvilTokens operation also carries particular relevance for organisations across Australia and the wider APAC region as businesses continue to rely heavily on cloud-based productivity platforms and digital communications.

Business Email Compromise remains an important enterprise risk because compromised accounts can be used to impersonate employees, redirect payments, access sensitive information or compromise trusted business relationships.

The emergence of platforms such as EvilTokens adds another layer to that risk by making sophisticated phishing capabilities available through an as-a-service model.

Moving beyond the MFA checkbox

The disruption of EvilTokens is a reminder that authentication security is increasingly about more than whether MFA is enabled.

As attackers develop ways to steal authentication tokens, maintain sessions and automate convincing phishing campaigns, organisations need to consider the entire identity and email security chain.

Cloudflare's recommendations point toward a layered approach combining phishing-resistant authentication, conditional access, session controls, email security and continuous threat detection.

For security teams, the broader lesson is that MFA remains important, but the way authentication is implemented and protected matters just as much as whether the control exists.


About Cloudflare

Cloudflare is a connectivity, security and developer services company operating a global network designed to connect organisations, applications and users while providing security and performance services. Its Cloudforce One team conducts threat intelligence research and works with industry and law enforcement partners on cyber threat investigations and disruption operations.


About Microsoft

Microsoft is a global technology company providing software, cloud computing, cybersecurity, productivity and artificial intelligence technologies. Its Digital Crimes Unit works to disrupt cybercrime through technical investigations, partnerships and legal action.


Source and Credits

Cloudflare Cloudforce One, “Cloudflare participates in global operation to disrupt EvilTokens Phishing-as-a-Service,” September 22, 2026.