Microsoft's 'EvilTokens' and MyLovely.AI Breach: Cyberattacks Are Already Unmasking You

Post date: April 13, 2026 · Discovered: April 17, 2026 · 4 posts, 20 comments

MyLovely.AI experienced a massive data dump, leaking 113,000 records containing user-created NSFW prompts, email addresses, and handles from Discord and X. Meanwhile, the threat of automated attacks, like Microsoft device-code phishing, is already compromising numerous organizations and stealing financial data.

The debate centers on online anonymity. One contingent points to AI's capability to reconstruct identities from minimal public data points, as noted by 'other_cat.' Conversely, 'x550' argues this fear is inflated, suggesting strict Operational Security (OPSEC) like account burning provides a viable defense. A more extreme defense, suggested by 'GamingChairModel,' advises completely segmenting online lives into separate accounts for different life categories.

The weight of opinion confirms AI poses an immediate, elevated threat from both industrial espionage and personal data theft. The central fault line remains: whether advanced behavioral modeling can render all online anonymity obsolete, or if rigorous, almost paranoid, user discipline can still build sufficient digital walls.

Key Points

SUPPORT

AI is weaponizing attacks via corporate credential theft.

The threat from Microsoft device-code phishing using automation to steal financial data is concrete.

SUPPORT

AI can rebuild identity from tiny data crumbs.

'other_cat' stated chatbots can figure out real identities from minimal public posts by cross-referencing data.

SUPPORT

High-profile data leaks are happening.

'lemmydev2' reported the 113,000 record breach from MyLovely.AI containing NSFW prompts and personal handles.

OPPOSE

OPSEC is sufficient to prevent doxing.

'x550' directly countered doxing fears, arguing users can mitigate risk through account burning and strict OPSEC.

SUPPORT

Radical account segmentation is necessary for privacy.

'GamingChairModel' advised maintaining completely separate accounts for distinct life topics (career vs. hobbies) to stop metadata linking.

Source Discussions (4)

This report was synthesized from the following Lemmy discussions, ranked by community score.

68
points
AI Can Now Easily Unmask Your Secret Online Life (Even If You Use a Fake Name)
[email protected]·20 comments·2/26/2026·by other_cat·itsfoss.com
23
points
113,000 explicit prompts from AI girlfriend platform exposed, many linked to user IDs
[email protected]·1 comments·4/9/2026·by lemmydev2·helpnetsecurity.com
20
points
Hundreds of orgs compromised daily in Microsoft device code phishing attacks
[email protected]·2 comments·4/7/2026·by lemmydev2·theregister.com
6
points
Inside an AI‑enabled device code phishing campaign
[email protected]·0 comments·4/13/2026·by digicat·microsoft.com