News Security

Cloudflare Disrupts EvilTokens MFA-Bypassing Phishing Operation

Ercan

Global operation exposes the growing cybercrime economy around stolen authentication tokens, AI-assisted phishing and Microsoft 365 account compromise.

Cloudflare has joined Microsoft’s Digital Crimes Unit, law enforcement agencies and industry partners in a coordinated operation to disrupt EvilTokens, a phishing-as-a-service (PhaaS) platform designed to bypass multi-factor authentication (MFA) and enable Business Email Compromise (BEC).

The operation highlights a significant shift in the phishing threat. Rather than relying solely on stolen passwords, EvilTokens was built to capture authentication tokens and exploit authenticated Microsoft 365 sessions, giving attackers a potential route around conventional MFA protections.

Cloudflare’s threat intelligence team, Cloudforce One, identified and disrupted malicious infrastructure associated with the platform, including hundreds of domains and malicious Cloudflare Worker projects. Microsoft pursued civil legal action to seize control of domains linked to attacks against its customers, while Cloudflare used network intelligence to identify and block additional infrastructure.

“As phishing-as-a-service continues to lower the technical barrier for attackers, collaboration between cloud providers, security teams, threat intelligence organisations, technology companies and law enforcement will be increasingly important to identify and disrupt criminal infrastructure before it can cause further harm.” — Ercan Aydin, AVP, Middle East, Turkey & Africa, Cloudflare

EvilTokens emerged on Telegram in January 2026 with a web-based criminal panel that automated the collection of authentication tokens. The platform also featured an AI coach capable of providing guidance for phishing scenarios involving BEC, tax documents, invoices and accounting communications—lowering the expertise required to create convincing social-engineering attacks.

For organisations across the Middle East and Africa, the incident underscores the broader risk surrounding Microsoft 365 and cloud collaboration environments. A compromised mailbox can expose legitimate conversations, contacts and financial workflows, giving attackers valuable context for highly targeted fraud.

The operation also reinforces why MFA cannot be treated as a standalone defence. Cloudflare recommends phishing-resistant authentication such as FIDO2, WebAuthn, hardware security keys and passkeys, combined with conditional access, session monitoring, email and DNS security, and properly configured DMARC, SPF and DKIM.

The broader lesson is that the cybercrime economy is increasingly packaging infrastructure, automation and AI-assisted social engineering as an accessible service. Disrupting that infrastructure therefore becomes as important as detecting individual phishing attempts.

Related posts

Kissflow Tops Gartner Peer Insights on Customer Reviews

Enterprise IT World MEA

Jaggaer Acquires Ivoflow to Bring AI Price Intelligence to Manufacturing

Enterprise IT World MEA

Nozomi Networks Bridges the OT Action Gap With Compass

Enterprise IT World MEA

Leave a Comment