By NHI Mgmt Group Editorial TeamBased on Abnormal AI: “Inside EvilTokens: The PhaaS Platform Stealing Tokens, Not Passwords” (June 26, 2026)

TL;DR: A phishing-as-a-service platform is using legitimate Microsoft sign-in flows to steal OAuth tokens instead of passwords, then turning that access into persistent business email compromise, according to Abnormal AI. The core problem is that traditional credential-harvesting controls assume a fake login page or stolen password, while token theft preserves legitimate authentication context and defeats those assumptions.


At a glance

What this is: This is an analysis of EvilTokens, a phishing-as-a-service platform that steals OAuth tokens through a real Microsoft sign-in flow and converts them into persistent business email compromise.

Why it matters: It matters because identity teams cannot rely on password-harvest detection alone when legitimate authentication is being abused to capture tokens and sustain mailbox access.


Context

OAuth token theft is a different failure mode from password phishing. The user authenticates on legitimate infrastructure, which means the usual fake-login-page signals may never appear even though access is being stolen.

For IAM and email security teams, the issue is not only initial compromise. A captured OAuth token can preserve access context long enough to support persistent business email compromise, which makes token lifecycle and behavioural detection more important than password-centric controls alone.

The article frames EvilTokens as a phishing-as-a-service platform that uses AI to automate business email compromise at scale, but the identity problem is still the same: trusted sign-in context is being turned into an attack primitive.


Key questions

Q: What breaks when OAuth tokens are stolen through a legitimate login flow?

A: Password-based phishing controls lose much of their value because the victim authenticates on real infrastructure and the attacker captures the token instead of a password. The result is reusable access that can outlast the session and support inbox compromise, so organisations need controls for token issuance, scope, and revocation.

Q: Why do compromised email accounts still create business email compromise risk?

A: Because once an attacker controls a valid mailbox, the messages often look legitimate to users and to some security tools. The attacker no longer needs to impersonate from outside the system. That is why account takeover, delegated access, and lifecycle gaps are the real drivers of business email compromise in cloud email environments.

Q: How do security teams know if OAuth abuse is slipping past detection?

A: The warning signs are gaps between user activity and identity telemetry. If sign-in logs look normal but browser behaviour shows unusual copy-paste, redirect, or code transfer patterns, the attack may already be in progress. Monitoring must include browser events, deprecated identity logs, and the specific application and resource IDs associated with suspicious consent activity.

Q: Should organisations prioritise token revocation or password resets after suspected compromise?

A: Token revocation usually comes first when the incident involves OAuth, refresh tokens, API keys, or other delegated access. Password resets help only if the attacker depended on interactive login. When the compromise path includes connected apps, the priority is to cut off every issued credential and consented integration before restoring user access.


Background and context

Why legitimate OAuth flows defeat password-harvesting controls

OAuth shifts the security boundary from password capture to token issuance. When a victim authenticates on real Microsoft infrastructure, the attacker does not need to steal a password or host a fake login page. Instead, the attacker captures the authorization artefact that follows a successful sign-in. That means tools tuned to detect lookalike pages, brand spoofing, or obvious credential replay can miss the attack path entirely. The relevant control question becomes whether the environment can distinguish a legitimate authentication event from the downstream misuse of the resulting token.

Practical implication: tune detection to token issuance, consent abuse, and post-authentication behaviour, not just phishing page indicators.

How captured OAuth tokens become persistent BEC access

OAuth tokens are bearer-style credentials that can grant access without re-entering a password, depending on scope and policy. Once stolen, they can be reused until expiry or revocation, which gives an attacker a durable foothold inside email and collaboration workflows. In business email compromise, that persistence matters more than one-time account takeover because it supports inbox monitoring, impersonation, and downstream fraud activity. The security issue is therefore lifecycle exposure: the token outlives the authentication event that created it.

Practical implication: treat token revocation and session invalidation as first-class incident response actions when OAuth abuse is suspected.

Why AI-assisted BEC changes the detection problem

The article says EvilTokens uses AI to automate business email compromise at scale. That changes operational tempo rather than the underlying identity primitive. Automation can increase the speed at which stolen access is used, but the main security challenge remains the same: the attack flows through a legitimate sign-in path and then turns authentication artefacts into unauthorized access. This is a governance problem for identity, email security, and fraud response working together, because the compromise surface spans consent, session, mailbox access, and message abuse.

Practical implication: correlate identity telemetry, mailbox activity, and fraud signals so token abuse does not look like routine user behaviour.


NHI Mgmt Group analysis

OAuth token theft is now a primary identity compromise pattern, not a niche variant of phishing. Traditional credential-harvesting assumptions are built around fake pages and stolen passwords, but this attack path keeps the sign-in experience legitimate while moving the theft point to the token itself. That shifts the governance problem from password protection to post-authentication control of bearer credentials. Practitioners should treat token theft as a mainstream identity risk, not an email-only anomaly.

Consent and token lifecycle are the real control boundary here. If an attacker can turn a valid Microsoft sign-in into a reusable token, the programme has already lost the point at which it expected trust to end. That means the important question is no longer just whether authentication succeeded, but whether issuance, scope, revocation, and reuse are governed tightly enough to make that success safe. The implication is that identity assurance must extend beyond login to the lifecycle of the token that follows.

Business email compromise is becoming an access-continuity problem. Once a stolen token carries enough privilege and lasts long enough to be operational, the attacker no longer needs password resets or repeated phishing. That is why email security teams, IAM teams, and fraud responders have to work from the same telemetry rather than separate assumptions. The programme-level lesson is that persistent access should be measured and governed as an identity outcome, not just a mailbox event.

Token theft exposes the gap between successful authentication and trustworthy access. A real login can still produce an untrustworthy session when the resulting credential is portable and reusable. That creates an identity blast radius that password-centric controls do not model well. Practitioners should re-evaluate how much of their access model assumes that a genuine login is sufficient proof of safe continuation.

OpenID Connect and OAuth controls matter because the attack uses the protocol, not a broken password. The issue is not simply misuse of a web login. It is unauthorized reuse of tokens issued by a legitimate federation and authorization flow. The implication is that identity teams need governance over delegated access paths, not only primary authentication events, because the attacker is operating inside the normal protocol boundary.

From our research library:

  • Across one million observed logins, 1 in 4 were password-based rather than SSO, 2 in 5 were not protected by MFA and 1 in 5 used a weak, breached or reused password.

What this signals

OAuth abuse is shifting identity defence away from password events and toward delegated-access governance. The practical consequence for IAM teams is that login success can no longer be treated as the end of the control path. Scope, consent, token reuse, and revocation behaviour become the real security boundary, especially where email and collaboration platforms are concerned.

Bearer tokens create a short but powerful trust window. When that window is not tightly governed, an attacker can convert one legitimate sign-in into persistent access for BEC, mailbox abuse, or secondary fraud. Teams should watch for signs that token lifetime and session invalidation are misaligned with the organisation's risk tolerance.


For practitioners

  • Harden OAuth consent governance Restrict app consent, review granted scopes, and investigate any token grant that creates mailbox or directory access beyond the expected user workflow.
  • Monitor for token abuse after valid logins Build detections around impossible behaviour for a newly issued token, including unusual mailbox rules, atypical send patterns, and first-time use from abnormal locations.
  • Shorten the value of captured tokens Reduce the lifetime and usefulness of bearer credentials where policy allows, and ensure revocation events actually invalidate active sessions and connected apps.
  • Join IAM and email telemetry Correlate sign-in events, OAuth grants, inbox rule changes, and outbound message anomalies so BEC investigations start from identity evidence, not only mail filtering alerts.

Key takeaways

  • OAuth token theft can defeat password-centric phishing defences because the victim completes a real sign-in while the attacker captures the token that follows.
  • The operational risk is persistence, since a stolen bearer token can keep mailbox access alive long after the initial login event.
  • Identity teams should treat consent, scope, and revocation as the primary control points for this attack pattern, not password hygiene alone.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10, OWASP API Security Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationThe attack abuses legitimate sign-in flows to capture tokens rather than passwords.
NHI-07 — Long-Lived SecretsCaptured OAuth tokens remain usable beyond the original login event.
NHI-10 — Human Use of NHIThe attack turns human sign-in into a machine-reusable credential theft event.
Recommendation — Review authentication flows for token theft paths and reduce trust in login success alone. Shorten token usefulness and validate that revocation actually ends active access. Separate human authentication signals from the lifecycle of the token they create.
OWASP API Security Top 10API2 — Broken AuthenticationToken misuse turns a valid authorization flow into unauthorized access.
Recommendation — Harden OAuth and API authentication paths so issued tokens cannot be reused outside policy.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe article centers on scope, consent, and entitlement misuse after login.
Recommendation — Apply entitlement review and token scope governance to reduce post-login abuse.
MITRE ATT&CKTA0006;TA0009 — Credential Access; CollectionThe threat captures reusable credentials and then uses them for mailbox abuse.
Recommendation — Map token theft to credential access and collection techniques in your detections.

Key terms

  • Authentication Token Theft: Authentication token theft is the unauthorized capture and use of a credential that proves a user, service, or agent has already authenticated. Technically, it includes stealing session cookies, bearer tokens, refresh tokens, or API tokens, then replaying them to bypass login controls and impersonate the original identity until the token expires or is revoked.
  • Bearer Token: A bearer token is a credential that grants access to whoever possesses it, without requiring strong proof that the holder is the intended client. In NHI environments, that makes theft and replay the main risk, especially when tokens are long-lived, broadly scoped, or stored in local files.
  • Business email compromise: A form of social engineering where an attacker impersonates a trusted person or domain to manipulate payment, change banking details, or extract sensitive information. It often succeeds without malware because the attacker targets process trust and human judgement instead of technical controls.
  • Consent Phishing: A social engineering attack that persuades a user to approve a malicious OAuth application. The attacker gains delegated access through legitimate authorization rather than stealing a password, which makes the resulting token-based access harder to detect and revoke than a normal sign-in compromise.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 27, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org