FBI Warns of Kali365 Microsoft 365 Phishing Scam
The FBI has issued a warning about a new phishing scam targeting Microsoft 365 users. The scam, known as Kali365, uses AI-generated emails and ready-made campaign templates to trick victims into entering their device code on a real Microsoft page.
This allows the attacker to capture the user's access tokens and bypass multi-factor authentication without stealing their password. The subscription model makes it easy for cybercriminals with little technical skill to rent the toolkit and start targeting victims immediately.
The FBI recommends creating conditional access policies that block or restrict device code flow for general users, auditing current usage, and blocking authentication transfer policies to prevent someone from moving a login session from a computer to a mobile device.