Snapshot from Jul 19, 2026 at 14:14 UTC. For live data and tracking: View Live
Regulatory phishing attack

FBI Warns Kali365 Phishing Targets Microsoft 365

Analysis based on 49 articles · First reported May 21, 2026 · Last updated Jun 28, 2026

Sentiment
-70
Attention
5
Articles
49
Market Impact
General
Live prominence charts, article sentiment distribution, and event development timeline available on the Ergen Dashboard

The Kali365 phishing scam poses a significant threat to businesses and individuals relying on Microsoft 365 services, potentially leading to data theft, fraud, and ransomware attacks. This could result in increased demand for cybersecurity solutions and services, impacting the cybersecurity industry positively, while potentially causing reputational and financial damage to affected organizations and Microsoft.

Cybersecurity Software Cloud Computing

The United States — Federal Bureau of Investigation has issued a warning about Kali365, a new phishing-as-a-service (PhaaS) platform distributed primarily via Telegram. This platform allows cybercriminals to bypass multi-factor authentication (MFA) and gain persistent access to Microsoft 365 accounts, including Microsoft Outlook, Microsoft, and OneDrive, by capturing OAuth tokens. The scam involves sending phishing emails that impersonate trusted cloud services, directing victims to legitimate Microsoft verification pages to enter a device code, unknowingly authorizing the attacker's device. Kali365 lowers the technical barrier for attackers by providing AI-generated phishing lures and automated campaign templates. The United States — Federal Bureau of Investigation recommends organizations restrict or block device code authentication, review existing usage, and report incidents to the United States — Internet Crime Complaint Center. Microsoft is actively working to disrupt such cybercriminal ecosystems.

stock
Microsoft's 365 services, including Microsoft Outlook, Teams, and OneDrive, are the primary targets of the Kali365 phishing scam. The company is actively working to disrupt cybercriminal ecosystems.
Importance 95.0 Sentiment -50.0
oth
Microsoft Outlook>>> is one of the key Microsoft>>> applications targeted by the Kali365 phishing scam, allowing cybercriminals to access emails and potentially sensitive information. This direct compromise affects its users' security.
Importance 90.0 Sentiment -60.0
oth
OneDrive>>> is another Microsoft>>> application vulnerable to the Kali365 phishing scam, enabling attackers to access and potentially steal files. This poses a risk to data integrity and privacy for its users.
Importance 90.0 Sentiment -60.0
govactor
The United States — Federal Bureau of Investigation issued a warning about the Kali365 phishing platform, detailing its methods and recommending mitigation strategies to protect users and organizations.
Importance 90.0 Sentiment 0.0
oth
OAuth>>> tokens are the digital keys captured by the Kali365 scam, allowing attackers to bypass multi-factor authentication and gain persistent access to Microsoft>>> accounts. This exploitation highlights a vulnerability in how these tokens are secured.
Importance 70.0 Sentiment -40.0
govactor
The United States — Internet Crime Complaint Center is the recommended platform for individuals and organizations to report incidents related to the Kali365 phishing kit.
Importance 60.0 Sentiment 0.0
priv
North American Cobalt Inc.>>> is one of the regions where thousands of Kali365 attacks have been reported, indicating a broad geographical impact of the scam. This highlights the widespread nature of the threat.
Importance 40.0 Sentiment -30.0
loc
Europe>>> is another region where the Kali365 phishing scam has been actively targeting organizations, demonstrating the international reach of this cyber threat. This indicates a global concern for cybersecurity.
Importance 40.0 Sentiment -30.0
oth
Bleeping Computer>>> reported on the Kali365 platform and its methods, contributing to the public awareness of the threat.
Importance 30.0 Sentiment 0.0
priv
Telegram is identified as the primary distribution channel for the Kali365 phishing-as-a-service platform.
Importance 30.0 Sentiment 0.0
stock
Proofpoint>>> is one of several cybersecurity firms that warned about hundreds of attacks involving hackers using Kali365 and similar phishing-as-a-service platforms.
Importance 20.0 Sentiment 0.0
priv
Arctic wolf researchers observed Kali365-linked activity, providing insights into the attackers' post-compromise actions.
Importance 20.0 Sentiment 0.0
priv
Huntress (company)>>> is one of several cybersecurity firms that noted the existence of multiple services akin to Kali365 offering similar capabilities.
Importance 20.0 Sentiment 0.0
stock
IBM>>> is one of several cybersecurity firms that noted the existence of multiple services akin to Kali365 offering similar capabilities.
Importance 20.0 Sentiment 0.0
oth
CyberScoop>>> is a security researcher mentioned as reporting that the Kali365 phishing kit can target any Microsoft>>> user. Its role is to provide information and analysis on cybersecurity threats.
Importance 10.0 Sentiment 0.0
+ 4 more entities View on Dashboard
ERGEN INTELLIGENCE
Track this event live

Set up alerts, explore entity relationships, search across thousands of events, and build custom intelligence feeds.

Open Dashboard

About Ergen

Ergen is a news intelligence platform that converts raw news articles into structured data. It tracks events, entities, and the relationships between them, with sentiment and attention metrics derived from thousands of articles. Pages on this site are daily static snapshots from the platform's live database. For real-time tracking, search, and alerts, the full dashboard is at app.ergen.ai.