October 1, 2026
How to Tell If Your Business Email Was Hacked (EvilTokens)
Microsoft took down EvilTokens after 12,000 Microsoft 365 inboxes were hacked for invoice fraud. Here’s the free 10-minute check for hidden…
By S6 Tech
6 min read
Microsoft took down EvilTokens after 12,000 Microsoft 365 inboxes were hacked for invoice fraud. Here's the free 10-minute check for hidden inbox rules.
Your Next Fake Invoice Will Come From a Real Email Thread
Microsoft just took down EvilTokens, a rented phishing kit that broke into more than 12,000 Microsoft 365 inboxes and used AI to hunt for invoices worth redirecting. Here's what it leaves behind, and the free 10-minute check that finds it.
— -
The receivables clerk at a building supply distributor had one call left on her Friday list. A general contractor, a customer for nine years, was a month late paying for the lumber on a school job.
The contractor's controller answered on the second ring and sounded puzzled. They had paid, he said. Two weeks ago, to the new account.
She asked him which new account.
The one in your email, he said, and he forwarded it while she waited.
The message sat inside the real thread about the school job, under the real invoice number, with her name and signature block at the bottom. The sender was her own address. Two short, polite lines explained that the company had changed banks and apologized for the trouble. It sounded exactly like her.
Below it was his reply confirming he had updated the payment details. That reply never reached her inbox.
She had never seen either one.
— -
What just happened
On September 22, Microsoft published a breakdown of EvilTokens, a phishing kit sold on Telegram by a group it tracks as Storm-2992. Buyers paid $1,500 up front and $500 a month, and since February they used it to take over more than 12,000 inboxes at more than 10,000 organizations. The same day, Microsoft's Digital Crimes Unit and its partners seized 50 websites and disabled more than 150 domains behind the service.
The way in was device code sign-in, a Microsoft feature built for smart TVs and conference room screens that have no keyboard. The phishing email shows a short code and a link to Microsoft's genuine sign-in page. Typing the code there approves a sign-in on the attacker's computer. If you're already signed in to Microsoft in that browser, you never see a password box or an MFA prompt. You paste, you confirm, and the attacker is in.
Think of a valet stand where you vouch for a stranger's claim ticket. The attendant is real, the car is yours, and the stranger drives off in it.
After the break-in, Microsoft saw attackers register a new device to the account within 10 minutes so they could stay signed in for the long term. They also set inbox rules that hide conversations. Then the kit's AI read the mailbox, sorting for people in finance, executive, and admin roles, and for wire transfer details, pending invoices, and executive correspondence. Dark Reading reports that it also mapped who holds payment authority to plan the next fraud. No crew reads 12,000 inboxes by hand, so the kit handed the reading to software.
Seizing websites stops the next phishing link from working. Rules and devices already inside an account stay there until someone removes them, and Microsoft tells affected organizations to do that themselves: revoke sessions, disable the attacker's devices, and watch for new inbox rules.
— -
Why your security alerts didn't help
Rank the things you'd expect to warn you, from least useful to most.
Start with your MFA. If you were already signed in, it never asked. If you weren't, it asked, and you answered it yourself on Microsoft's real page.
The sign-in record comes next. It shows a genuine Microsoft page and a completed code, so the entry looks like any other Tuesday.
Your antivirus has nothing to catch, because nothing ran on your computer. The attacker reads your mail from their own machine using access you approved, and the AI does its sorting there.
Your team's scam instincts fare no better. Training teaches people to look for typos, strange senders, and odd links. The fraud email comes from a real account, lands in a real thread, and cites a real invoice number, so none of those signs show up.
A new password feels like cleanup. Microsoft's checklist for a compromised mailbox handles revoking sessions, reviewing forwarding, and removing inbox rules as separate steps, because a rule lives in the mailbox and a password change leaves it alone.
What works is the mailbox itself. To keep reading without being noticed, the intruder has to change something you can see: a rule that hides replies, a forward to an outside address, a device on the account that nobody recognizes. Microsoft's own list of warning signs includes rules that move messages into the Notes, Junk Email, or RSS Subscriptions folders. Nobody at a building supply company files invoices under RSS Subscriptions.
— -
What you can actually do this week
If you haven't blocked device code sign-in, Microsoft's Conditional Access policy takes 15 minutes and closes the door this kit used. It needs Business Premium or Entra ID P1. The three steps below check whether anyone already came through.
-
Look for rules nobody made. Free. 10 minutes per mailbox. Have each person open Outlook, then Settings, Mail, Rules. Any rule they didn't create that moves, deletes, marks as read, or forwards mail gets a screenshot, gets reported to you, and gets deleted. If you find one, open the Microsoft 365 admin center, go to Users, then Active users, pick that person, and choose Sign out of all sessions. Then call your IT provider the same day and ask them to remove any device on that account nobody recognizes.
-
Set outside forwarding to Off yourself. Free. 5 minutes. Microsoft 365 defaults to a setting called Automatic, System-controlled, and Microsoft's documentation says it behaves differently from one organization to the next, so choose Off on purpose. You'll find it at security.microsoft.com/antispam, in the outbound policy under Forwarding rules. On Google Workspace, go to the Admin console, then Apps, Google Workspace, Gmail, End User Access, and uncheck automatic forwarding.
-
Warn your customers before your mailbox does. Free. 15 minutes. Add one line to your invoice template and your email signature: Our bank details will never change by email. If a message says they have, call us at the number you already have before you pay. Send that line today to the customers who pay you the most. The kit's AI goes looking for the people who pay you, which makes them the ones best placed to catch the fake.
— -
The harder truth
EvilTokens was designed around small business paperwork. Its 44 email themes include construction bids, invoices, requests for proposals, document signing, and compensation notices. Microsoft named the industries it went after: wholesale distribution, construction, financial services, real estate, higher education, and healthcare. A few buyers did most of the damage, too. In data from the security firm SpyCloud, the 10 most active customers accounted for 60 percent of the unique victims.
The ransomware leak sites I track show the same targets from the other end. This week they named 92 victims from 18 crews. Storm posted four California companies in under a day, among them a vacuum fastener maker with 11 to 50 employees, each with an October 7 deadline. A crew called Emperador wants $150,000 from a Texas equipment rental company. Healthcare took seven hits from five different crews and has made my sector table in every issue since late June.
The FBI logged 24,768 business email compromise complaints last year, with losses just over $3 billion, about $123,000 per complaint. That fraud used to take a patient person reading someone else's inbox for days, waiting for an invoice worth hijacking. EvilTokens rented that job out to anyone who paid the subscription.
Microsoft took the kit offline. If a device had been added to your bookkeeper's account back in the spring, what in your office would have told you?
— -
If this was useful
I write S6 Ransomware Signal](https://s6-ransomware-signal.beehiiv.com/)**), a free weekly newsletter for small and mid-size businesses without a dedicated security team. Every Monday it turns the week's ransomware activity into plain English and a short list of fixes.
This week's issue also covers Storm-2570, a crew that has deployed four different ransomware brands while its toolkit barely changed, and the remote control software that has now turned up in six issues running. There's the lobby screen server, the kind that runs menu boards and waiting room displays, that let an attacker in through a flaw Samsung fixed in May 2025. And there's vladivostok, a ransomware program that opened on September 28 and is openly recruiting disgruntled employees.
Subscribe here.](https://s6-ransomware-signal.beehiiv.com/subscribe).**) It's free.
EvilTokens is offline. Whatever it left in a mailbox stays there until somebody opens the Rules page and looks.