FBI Warns Kali365 Phishing Targets Microsoft 365
Analysis based on 49 articles · First reported May 21, 2026 · Last updated Jun 28, 2026
The Kali365 phishing scam poses a significant threat to businesses and individuals relying on Microsoft 365 services, potentially leading to data theft, fraud, and ransomware attacks. This could result in increased demand for cybersecurity solutions and services, impacting the cybersecurity industry positively, while potentially causing reputational and financial damage to affected organizations and Microsoft.
The United States — Federal Bureau of Investigation has issued a warning about Kali365, a new phishing-as-a-service (PhaaS) platform distributed primarily via Telegram. This platform allows cybercriminals to bypass multi-factor authentication (MFA) and gain persistent access to Microsoft 365 accounts, including Microsoft Outlook, Microsoft, and OneDrive, by capturing OAuth tokens. The scam involves sending phishing emails that impersonate trusted cloud services, directing victims to legitimate Microsoft verification pages to enter a device code, unknowingly authorizing the attacker's device. Kali365 lowers the technical barrier for attackers by providing AI-generated phishing lures and automated campaign templates. The United States — Federal Bureau of Investigation recommends organizations restrict or block device code authentication, review existing usage, and report incidents to the United States — Internet Crime Complaint Center. Microsoft is actively working to disrupt such cybercriminal ecosystems.
Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.
Open Dashboard