EvilTokens Compromised 12,000 Inboxes and Let AI Choose the Next Victim

The AI did more than write convincing phishing messages. It read stolen mailboxes, mapped trust and told criminals which relationships were most valuable to abuse.

The AI did more than write convincing phishing messages. It read stolen mailboxes, mapped trust and told criminals which relationships were most valuable to abuse.

Alleged Entra directory theft exposed organisational maps rather than passwords. Treat bulk directory reads as a high-impact identity event.

Update, 22 August 2026: Microsoft has told BleepingComputer that it mistakenly marked a maximum-severity Microsoft Entra ID vulnerability as exploited in the wild. The correction removes the strongest public claim behind the first version of this article. It does not…

Microsoft will retire its Entra SMS and voice authentication service in February 2027, making passkey migration and exception governance urgent.

Choose a safe Active Directory DNS namespace using a registered domain, internal subdomain, verified UPN suffix and current Microsoft guidance.