MEDIUMPhishing
Global

FBI warns of Kali365 phishing service targeting Microsoft 365 accounts

·Source: BleepingComputer

Updated:

Executive Summary

The FBI is warning about the Kali365 phishing-as-a-service platform (PhaaS) that is used to hijack Microsoft 365 accounts by abusing OAuth device code authentication to steal session tokens and bypass multi-factor authentication (MFA). [...]

Analysis

The FBI is warning about the Kali365 phishing-as-a-service platform (PhaaS) that is used to hijack Microsoft 365 accounts by abusing OAuth device code authentication to steal session tokens and bypass multi-factor authentication (MFA). [...]
Source Attribution

Originally published by BleepingComputer on May 25, 2026.

Related Threats