The Phishing Kit Cost $2,000. The Average Loss: $123,005.

A phishing service that Microsoft disrupted this week sold for $1,500, plus $500 a month. According to Microsoft, it was used to break into more than 12,000 inboxes at more than 10,000 organisations in seven months.


Last updated: September 24

Key takeaways

Link copied
  • It abused device code sign-in, so the victim completed multi-factor authentication and approved the attacker's session.
  • EvilTokens sold for $1,500 plus $500 a month and was tied to more than 12,000 inbox compromises since February.
  • After entry, its AI filtered for finance and executive roles and searched mailboxes for wire details and invoices.
  • The FBI logged 24,768 business email compromise complaints in 2025 with $3.05bn of reported losses.
  • That is about $123,005 per complaint, or more than 20 years of the kit's subscription for one success.
  • Revoking sessions can leave access tokens valid for up to an hour, so Microsoft advises disabling the account.

Data highlight

123005US dollars

Average reported loss per business email compromise complaint to the FBI in 2025, against a phishing kit costing $2,000 for its first month

February 2026 to 24 September 2026

Compiled by HaiPay on 24 September 2026. Platform details, prices and victim counts are from the Microsoft Threat Intelligence, Microsoft Defender Experts and Microsoft Security Research post Unmasking EvilTokens: Getting to the root of device code phishing, published 22 September 2026, which states that EvilTokens emerged in February 2026, that campaigns using it compromised more than 12,000 inboxes in more than 10,000 organisations worldwide, that the kit sold for $1,500 with a $500 monthly subscription and further fees for add-on products including an antibot redirector, bulk senders and a capture link, that it offered 44 lure themes including invoices and requests for proposals, that the seller is tracked as Storm-2992 and advertised on Telegram, that the device code window is 15 minutes and the attacker script polls the state endpoint every three to five seconds, that attackers registered new devices within ten minutes of a breach in some cases to obtain a primary refresh token, that the platform used AI to filter compromised users for financial, executive and administrative roles and searched those mailboxes for wire transfer details, pending invoices and executive correspondence, and that revoking sign-in sessions may leave existing access tokens valid for up to an hour, which is why Microsoft advises temporarily disabling a compromised account. Observed victim concentrations were in the United States, Canada, the United Kingdom, Australia, India and France, across wholesale distribution, construction, financial services, real estate, higher education and healthcare. Loss figures are from the FBI Internet Crime Complaint Center 2025 Internet Crime Report, which records 24,768 business email compromise complaints and $3,046,598,558 in reported losses for that crime type in 2025. HaiPay divided the two to get an average of $123,005 per complaint; the FBI does not publish that average, complaints are victim-reported rather than a complete measure of business email compromise, and a mean is pulled upward by a small number of very large cases. The two datasets are independent and do not overlap. Victim counts and attribution are Microsoft's own telemetry and could not be independently verified by HaiPay. News reports of arrests in the United Kingdom in connection with the service were not confirmed by any police statement HaiPay could find on 24 September 2026 and are not reported here as fact. HaiPay did not contact Microsoft, the FBI or any other organisation.

A phishing service that Microsoft disrupted this week sold for $1,500, plus $500 a month. According to Microsoft, it was used to break into more than 12,000 inboxes at more than 10,000 organisations in seven months.

The average business email compromise reported to the FBI last year cost the victim about $123,000.

Microsoft's Digital Crimes Unit and its threat intelligence teams published their account of the platform, called EvilTokens, on 22 September, alongside a coordinated takedown of the infrastructure behind it.

What the money bought

EvilTokens was sold as a service, advertised and supported through Telegram channels, with the seller tracked by Microsoft as Storm-2992. The price was $1,500 to buy in and $500 a month to keep the kit and its control panel. Extras, including a redirector to filter out security scanners, bulk senders and a capture link, cost more for each 30 days.

Subscribers got 44 ready-made lure themes, among them invoices and requests for proposals, plus an AI assistant that wrote the phishing email to fit the target's role. Referring another criminal to the service earned a reward in cryptocurrency.

Table of what the EvilTokens phishing service charged, 1,500 dollars to buy and 500 dollars a month, beside a bar chart comparing that 2,000 dollar first month with the 123,005 dollar average loss per business email compromise complaint reported to the FBI in 2025.


Why it defeated multi-factor authentication

The technique is device code phishing, and it works because the victim does the authenticating.

Device code sign-in is a legitimate flow built for screens that cannot handle a keyboard, such as smart TVs and conference room hardware. The device shows a short code, and the user types it into a browser somewhere else.

In the attack, the criminal's page asks Microsoft for a live code and shows it to the victim, often copying it to the clipboard automatically. The victim then goes to the genuine microsoft.com/devicelogin page and enters it, passing multi-factor authentication in the process. What they have actually approved is the attacker's session.

No password is stolen. No fake login page has to survive inspection. The only thing the criminal needs is for someone to paste a code within the 15-minute window, and the attacker's script checks every three to five seconds to see whether that has happened.

Diagram of the device code phishing chain from lure email to a code generated by the attacker, pasted by the victim on the genuine Microsoft sign-in page, to a token reaching the attacker and an AI search of the mailbox for wire transfer details and pending invoices.


The part that concerns payments

Access to an inbox is not the goal. Microsoft's description of what happened next reads like a specification for invoice fraud.

The platform's AI filtered the pool of compromised users for people in financial, executive or administrative roles. It then used Microsoft Graph to map the organisation and its permissions. For the accounts with financial authority, the operators searched the mailbox for wire transfer details, pending invoices and executive correspondence.

Persistence was built to outlast the first alarm. In some cases attackers registered a new device within ten minutes of the breach to obtain a longer-lived token. In others they waited hours before creating inbox rules that hid their replies, the classic tell of a redirected payment.

Microsoft also warns of a gap that matters for any incident response run by a payments team: revoking a user's sessions typically invalidates refresh tokens but can leave existing access tokens working for up to an hour, which is why it advises temporarily disabling the account instead.

The arithmetic

Set the two numbers side by side.

Buying the kit and running it for a month cost $2,000. The FBI's Internet Crime Complaint Center logged 24,768 business email compromise complaints in 2025 with $3.05 billion in reported losses, which works out at about $123,005 per complaint.

One average success covers more than 20 years of the subscription. That is the economics that keeps phishing-as-a-service in business, and no takedown changes it.

What this is not

The victim counts are Microsoft's own telemetry and attribution, describing a platform used by many subscribers rather than the work of one gang. HaiPay could not independently verify them.

The FBI figures are victim-reported complaints, not a measure of all business email compromise, and they do not overlap with Microsoft's data. The per-complaint average is HaiPay's division of the FBI's reported losses by its complaint count, and is not a number the FBI publishes. Averages also hide a skew: a handful of very large cases pull the mean well above the typical loss.

News reports say arrests were made in the United Kingdom in connection with the service. HaiPay did not find a police statement confirming that today and does not report it as fact.

What to watch

Whether device code flow starts being blocked by default rather than by policy. Microsoft's own advice is to block it wherever it is not needed.

Whether the kit returns under another name. Phishing-as-a-service platforms usually do, and the price list is the clearest signal that demand is intact.

And whether payment controls catch what email controls missed. Every step in this chain after the token theft was a person reading invoices, which is exactly what payee verification and callback procedures exist to defeat.

How to cite

Link copied

HaiPay News, "The Phishing Kit Cost $2,000. The Average Loss: $123,005.", https://www.haipay.net/news/eviltokens-phishing-kit-bec-economics, September 24th, 2026

About the author

Crystal

Digital Public Relations

A digital PR specialist with a Master's in Journalism & Communication from UNSW. Started as an intern at ABC Australia, now leads public relations at Haipay, crafting press releases and media strategies that bring brand stories to life.

Reviewed by WeiJun TangEditorial policy

4 sources

Discover More