WhoshouldIsee Tracks

EvilTokens Explained: How Device Code Phishing Bypasses MFA and Enables AI-powered BEC 

EvilTokens Explained: How Device Code Phishing Bypasses MFA and Enables AI-powered BEC 

Built on original threat research from Abnormal AI, this briefing explores how EvilTokens uses device code phishing to compromise Microsoft 365 accounts without stealing passwords, even when MFA is in place. Discover how stolen access tokens can enable email fraud, how AI is changing business email compromise (BEC), and practical steps to reduce your organisation’s exposure. 

BlueFort connects the research to the security decisions that matter for your organisation. We explore identity and email security as two parts of the same attack chain, helping you understand where protections need to work together and how to prioritise practical improvements. 

With a Microsoft 365 security checklist and clear next steps, the report helps you assess your current approach, identify potential gaps and turn threat insight into action. You’ll also learn how an email security risk assessment with BlueFort and Abnormal AI can help you better understand your exposure and guide a conversation with a BlueFort Security Specialist. 

Download the threat briefing to understand the attack, review your defences and take practical steps to strengthen Microsoft 365 security. 

Download Now