Authentication can be genuine while the session receiving the authority is not the one the user intended.
Microsoft’s Digital Crimes Unit says EvilTokens compromised more than 12,000 inboxes across more than 10,000 organizations by abusing the legitimate OAuth device-code flow. Once inside, AI analyzed mailboxes to identify trusted relationships, payment processes, and likely financial targets. Microsoft coordinated a court-authorized disruption with partners and law enforcement.
The continuity failure
The user really authenticated, but the authentication event was not strongly bound to the session and purpose the user believed they were authorizing.
The GovKM interpretation
The attacker then used organizational records as institutional memory, reconstructing who trusts whom and who controls money. Authentication continuity and institutional-memory protection are therefore part of the same chain.
Continuity path: Authority/user authentication → Context/intended session → Decision/authorize → Action/attacker access → Record/mailbox → Institutional Memory/relationships → Future Reuse/fraud.
Sources
Microsoft Digital Crimes Unit and Microsoft Security Blog, September 22, 2026.


