FBI Warns Global Microsoft 365 Users of Kali365 Phishing Scam Bypassing MFA
The FBI has issued an urgent warning about Kali365, a sophisticated Phishing-as-a-Service (PhaaS) platform. This scam targets Microsoft 365 users, including those on Teams, Outlook, and OneDrive, by exploiting a legitimate authentication flow to steal access tokens and bypass multi-factor authentication without requiring a password.
Key Highlights
- FBI warns about 'Kali365' Phishing-as-a-Service (PhaaS) platform.
- Scam targets Microsoft 365 services like Outlook, Teams, and OneDrive.
- Bypasses multi-factor authentication (MFA) via device code phishing.
- Attackers steal OAuth tokens without needing user passwords.
- Kali365 platform offers AI-generated lures to less-skilled attackers.
- Impacts users and organizations globally, including in India.
The Federal Bureau of Investigation (FBI) has issued a critical public service announcement (PSA) warning users and organizations worldwide, including India, about a sophisticated phishing-as-a-service (PhaaS) platform known as 'Kali365'. This platform poses a significant threat to Microsoft 365 users, specifically targeting services such as Outlook, Teams, and OneDrive. The FBI's warning, released on May 21, 2026, highlights Kali365's ability to compromise Microsoft 365 accounts by stealing access tokens and effectively bypassing multi-factor authentication (MFA) without ever requiring a user's password.
Kali365 emerged in April 2026 and has since been distributed primarily through Telegram, making advanced phishing capabilities accessible to a broader range of cybercriminals, including those with limited technical expertise. The platform provides subscribers with a comprehensive toolkit, including AI-generated phishing lures, automated campaign templates, real-time dashboards for tracking targeted victims, and the crucial capability to capture OAuth tokens.
The modus operandi of Kali365 deviates from traditional phishing methods that rely on tricking users into entering credentials on fake login pages. Instead, it exploits a legitimate Microsoft feature known as the 'device code flow' (OAuth 2.0 Device Authorization Grant). The attack typically begins with a phishing email disguised as a message from a trusted cloud productivity or document-sharing service. This email contains a device code and instructs the recipient to visit a legitimate Microsoft verification page (e.g., microsoft.com/devicelogin) and enter the provided code.
Crucially, when the user enters the code on the genuine Microsoft page, they are unknowingly authorizing the attacker's device to access their Microsoft 365 account. This process allows the cybercriminal to capture OAuth access and refresh tokens, granting them persistent, unauthorized access to the victim's Microsoft 365 environment without needing the password or triggering subsequent MFA challenges for their own login. Once inside, attackers can access emails, files, chat history in Teams, and other sensitive information, potentially leading to data exfiltration, business email compromise (BEC) attacks, or further compromises within the organization.
Security researchers, including those from Arctic Wolf, have been tracking widespread campaigns utilizing the Kali365 platform since early April 2026. Hundreds of Kali365 attacks were documented in April alone, affecting organizations across North America, Europe, the Middle East, and Africa. A similar PhaaS platform, 'EvilTokens,' also leveraging device code phishing, has been observed compromising over 340 Microsoft 365 organizations across various countries, including the United States, Canada, France, Australia, India, Switzerland, and the UAE, impacting sectors like financial services, healthcare, and manufacturing. This underscores the global nature of this threat and its direct relevance to an Indian audience, given the widespread adoption of Microsoft 365 in the region.
To protect against such sophisticated attacks, the FBI and cybersecurity experts recommend several measures. Organizations should consider restricting or completely blocking device code authentication flows using Conditional Access policies where possible and regularly audit existing device code usage. It's also vital to block authentication transfer policies that allow sessions to move between devices. For individual users, vigilance is key: verify sender addresses for any suspicious emails, avoid clicking unfamiliar links or attachments, and instead navigate directly to the official service's website. Implementing strong, unique passwords and using physical hardware tokens for multi-factor authentication, if available, are additional robust protective steps. Any suspicious activity, including unauthorized device registrations or phishing emails, should be reported to the FBI's Internet Crime Complaint Center (IC3.gov).
The emergence of Kali365 represents a significant evolution in phishing tactics, moving beyond simple credential theft to exploit legitimate authentication mechanisms. Its accessibility as a PhaaS platform lowers the technical barrier for attackers, making this a pervasive and challenging threat for both individuals and enterprises globally.
Frequently Asked Questions
What is Kali365 and how does it work?
Kali365 is a Phishing-as-a-Service (PhaaS) platform that enables cybercriminals to launch sophisticated phishing attacks. It works by sending phishing emails that trick Microsoft 365 users into entering a device code on a legitimate Microsoft verification page, thereby unknowingly granting attackers access to their Microsoft 365 accounts by stealing OAuth tokens and bypassing multi-factor authentication (MFA).
Which Microsoft 365 services are affected by the Kali365 scam?
The Kali365 scam specifically targets popular Microsoft 365 services, including Outlook, Teams, and OneDrive, allowing attackers to gain persistent access to these platforms and the data stored within them.
Can Kali365 bypass multi-factor authentication (MFA)?
Yes, Kali365 is designed to bypass traditional MFA mechanisms. It does this by exploiting the legitimate Microsoft device code flow, which allows attackers to steal access tokens and gain entry to accounts even when MFA is enabled, without needing the user's password.
What can users and organizations do to protect themselves from Kali365?
To protect against Kali365, users should be highly vigilant about suspicious emails, avoid clicking unfamiliar links, and navigate directly to official websites. Organizations are advised to restrict or block device code authentication flows using Conditional Access policies, regularly audit usage, and report any suspicious activity to the FBI's IC3.gov. Using strong, unique passwords and hardware tokens for MFA are also recommended.
Is this a global threat, and is India affected?
Yes, the Kali365 threat is global. While the FBI issued the warning, campaigns have been observed across North America, Europe, the Middle East, and Africa. Related device code phishing attacks (like EvilTokens) have specifically impacted organizations in India, highlighting the direct relevance and risk to the Indian audience.