FBI Warns of Kali365 Phishing Scam Targeting Microsoft 365 Users
The FBI has issued a warning about a phishing kit called Kali365 that allows cybercriminals to capture Microsoft 365 access tokens and bypass multi-factor authentication.
Kali365 was first spotted in April 2026 and is sold as a subscription service through Telegram, making it accessible to individuals with limited technical skills.
The phishing scam works by sending AI-generated emails that include a short device code. The victim then enters the code on Microsoft's real device login page, thinking they are verifying themselves.
However, this actually authorizes the attacker's device to access the account instead of the user's own, allowing the attacker to hold an OAuth token and maintain persistent access to Outlook email, Teams chats, and OneDrive or SharePoint files.
The FBI recommends that business owners create a conditional access policy that blocks or restricts device code flow for general users, audit current usage to avoid locking out legitimate processes, and block authentication transfer policies.