The latest disruption disables websites and domains, but unauthorized sessions may persist; investigators have not published how many victims were remediated
Blocking the websites and scripts behind a phishing service can prevent victims from reaching its traps. However, this does not automatically eject attackers from email accounts they have already entered.
That distinction matters — after the September 2026 disruption of EvilTokens, a service used to obtain access to Microsoft 365 inboxes.
The attackers did not need to steal passwords. Their phishing pages gave victims a code to enter on a legitimate sign-in page. Completing the sign-in authorised an attacker-controlled session, potentially including access and refresh tokens. A password reset alone may not end that access if the sessions and tokens remain valid.
Also, the phishing service’s delivery infrastructure extended beyond any one set of domains. In March 2026, researchers had traced EvilTokens-linked campaigns through compromised websites, online services and short-lived phishing pages hosted on a serverless platform. They reported the pages they observed to the host and said most, if not all, had already been removed. However, that earlier action did not end the campaigns, according one report. The September intervention went further…
Taking civil action against phishing syndicates
A US civil action has enabled the seizure of 50 websites used to operate EvilTokens, and the disabling of more than 150 supporting domains, according to plaintiffs, Microsoft and Health-ISAC.
A hosting provider had testified that it had banned hundreds of associated domains and serverless projects, and put warning pages in front of some phishing links it could not seize.
Another entity, Cloudflare, has testified that it has taken action against domains and phishing pages and scripts hosted on its serverless computing platform.
Nevertheless, published figures describing how the syndicate infrastructure has been affected, could not tally the number of campaigns stopped or accounts secured.
An unanswered question
For organisations investigating exposure, the relevant question is whether employees completed the device-code sign-in and whether unauthorised sessions remain active.
The infrastructure takedown cannot answer either question for an individual account. There is also no public evidence yet that EvilTokens cannot resume operations using replacement infrastructure.
Microsoft has notified affected customers and helped remediate compromised accounts; it has not published a count of accounts remediated.
For now, the UK police has arrested two men in a related investigation in early September 2026. Both were released on bail while inquiries continue.
