News

Criminals using a phishing service called EvilTokens circumvented conventional MFA protections to take over Microsoft 365 accounts, according to a technical analysis Microsoft published Sept. 22. Victims signed in on Microsoft’s own login page, unknowingly authorizing the attackers’ session. The service was linked to more than 12,000 compromised inboxes at over 10,000 organizations, including some in healthcare, between February and its takedown. Microsoft and its partners seized 50 websites and disabled more than 150 additional domains. London’s Metropolitan Police arrested two men Sept. 11 in connection with the alleged operation. Because healthcare organizations were targeted, Health-ISAC joined Microsoft’s lawsuit against the operators as a co-plaintiff, according to the group’s announcement. Health-ISAC also joined Microsoft’s earlier cases against Cobalt Strike abuse in 2023 and the RaccoonO365 phishing service in 2025.

The attack comes as federal policymakers are considering broader MFA requirements for healthcare organizations. A House discussion draft and HHS’s pending HIPAA Security Rule rewrite, covered here Sept. 16, would both require MFA. However, neither specifies which kind of MFA. The ShinyHunters campaign covered here Sept. 10 also circumvented MFA protections, relaying passwords and one-time codes to real login portals during phone calls. EvilTokens did not need to steal victims’ credentials, shifting the defense from password protection toward controlling authentication flows and tokens.

How Device Code Phishing Works

Device code sign-in exists for equipment that has no practical way to type a password, according to Microsoft. For example, smart TVs, printers, Teams devices and conferencing systems use it. Specifically, the EvilTokens phishing page requested a live code from Microsoft and sent the victim to Microsoft’s real device login page. The victim entered the code and completed Microsoft’s normal sign-in process, which authorized the attacker-controlled session and issued tokens that gave the attacker access to the account. In some cases, attackers registered new devices within 10 minutes to obtain a Primary Refresh Token and establish longer-term access, Microsoft said.

Greg Sieg, CISO of University of Michigan Regional Health Network, described the general problem of attackers who get past MFA when he told healthsystemCIO in June about cyber resilience. “They get past layer one, they’ve got a phishing event, but now I’ve got MFA to protect layer two,” he said. “Well, now they get past MFA, so how do I protect that next layer down?”

AI Tools Helped Identify Fraud Targets

After an account was compromised, EvilTokens’ AI tools could summarize email, identify financial conversations and map staff roles, according to Microsoft’s announcement. Preset prompts also offered to find wire-transfer discussions, vendor invoices, the people who move money and the best people to impersonate. It was also Microsoft’s Digital Crimes Unit’s first action against what the company called an end-to-end AI-enabled cybercrime service. In July, Errol Weiss, Health-ISAC’s chief security officer, told healthsystemCIO about the security priorities he urges on hospitals. AI, he said, “does nothing but speed up this whole process and change the dynamics of how people need to react.”

Microsoft’s first recommendation is to block device code flow wherever possible. Where a device needs it, Microsoft advises allowing it only through Entra ID Conditional Access policies scoped to that device. In addition, access could survive a password reset if the victim’s sessions and tokens were not also revoked, Microsoft said. Microsoft also advises confirming requests to change payment details or redirect funds through a trusted second channel. Microsoft continues to recommend MFA, particularly phishing-resistant methods such as FIDO tokens and passkeys. EvilTokens also illustrates why an MFA mandate alone does not eliminate identity-based attacks: the strength of the authentication method and the controls around legitimate authentication flows still matter.

Get the next one in your inbox.

New interviews and webinars with health system IT, security and informatics leaders.

Related Articles

ShareShare
We will be happy to hear your thoughts

Leave a reply

Som2ny Network
Logo
Register New Account
Compare items
  • Total (0)
Compare
0
Shopping cart