GovKM
Authentication Context and Institutional Reconstruction

The Login Was Real. The Session Wasn’t.

Microsoft’s EvilTokens disruption shows how a legitimate authentication event can become detached from the intended session, after which AI can reconstruct organizational authority from mailbox records.
Trust illustration representing a legitimate user authentication event being bound to an attacker-controlled session that then uses AI to reconstruct organizational relationships from the mailbox.
Expand image

Authentication can be genuine while the session receiving the authority is not the one the user intended.

Microsoft’s Digital Crimes Unit says EvilTokens compromised more than 12,000 inboxes across more than 10,000 organizations by abusing the legitimate OAuth device-code flow. Once inside, AI analyzed mailboxes to identify trusted relationships, payment processes, and likely financial targets. Microsoft coordinated a court-authorized disruption with partners and law enforcement.

The continuity failure

The user really authenticated, but the authentication event was not strongly bound to the session and purpose the user believed they were authorizing.

The GovKM interpretation

The attacker then used organizational records as institutional memory, reconstructing who trusts whom and who controls money. Authentication continuity and institutional-memory protection are therefore part of the same chain.

Continuity path: Authority/user authentication → Context/intended session → Decision/authorize → Action/attacker access → Record/mailbox → Institutional Memory/relationships → Future Reuse/fraud.

Sources

Microsoft Digital Crimes Unit and Microsoft Security Blog, September 22, 2026.

RELATED KNOWLEDGE

Continue Exploring

Explore related research, framework domains, and continuity concepts.
CONTINUE WITH THE FRAMEWORK

Explore the continuity relationships that support trustworthy organizational intelligence.

Continue through the GovKM Framework to examine the doctrine, knowledge, and implementation guidance behind Organizational Continuity.