The CEO RegisterThe CEO RegisterThe CEO Register
Font ResizerAa
  • Latest News
  • Business
  • World
  • Women
  • Entrepreneurs
  • StartUps
  • Technology
  • Success Stories
Font ResizerAa
The CEO RegisterThe CEO Register
  • My Saves
  • My Interests
  • My Feed
  • History
  • Technology
  • World
Search
  • Latest News
  • Business
  • World
  • Women
  • Entrepreneurs
  • StartUps
  • Technology
  • Success Stories
  • Personalized
    • My Saves
    • History
Have an existing account? Sign In
Follow US
Latest NewsTechnology

FBI Warns Low-Skill Scammers Can Now Hijack Microsoft Accounts Using New Toolkit

Last updated: May 29, 2026 3:57 am
The Editorial Desk
Share
Kali365 phishing scam
SHARE

FBI Warns About Kali365 Scam That Can Bypass Microsoft 365 Security Without Stealing Passwords.

Cybercriminals are increasingly finding ways to bypass traditional security measures, and a new phishing toolkit known as Kali365 is raising concerns among cybersecurity experts and law enforcement agencies.

The Federal Bureau of Investigation (FBI) has issued a warning about the fast-growing scam, which targets Microsoft 365 users by capturing authentication tokens instead of stealing passwords. The technique allows attackers to gain access to services such as Outlook, Teams, and OneDrive while bypassing multifactor authentication (MFA), one of the most widely used security protections today.

Security researchers say the emergence of Kali365 highlights a shift in cybercrime tactics, where attackers focus on exploiting authentication systems rather than simply collecting usernames and passwords.

What Is Kali365?

Kali365 is a subscription-based phishing platform designed to help cybercriminals launch sophisticated attacks against Microsoft 365 users.

First identified in April 2026, the platform has reportedly been promoted through Telegram channels and underground cybercrime communities. According to cybersecurity company Bitdefender, access to the service costs as little as $250 per month or $2,000 annually.

What makes Kali365 particularly concerning is its ability to automate attacks that previously required advanced technical knowledge.

The FBI says the platform provides attackers with:

  • AI-generated phishing messages
  • Automated phishing campaign templates
  • Real-time target tracking tools
  • OAuth token capture capabilities

By packaging these tools into a ready-made service, Kali365 significantly lowers the barrier to entry for cybercriminals.

How The Attack Works

Unlike traditional phishing scams that attempt to steal passwords through fake login pages, Kali365 focuses on OAuth device codes.

OAuth is a widely used authorization system that allows applications to access user accounts without repeatedly requiring passwords. Microsoft uses this system across many of its cloud-based services.

The attack typically begins when a victim receives a phishing email that appears to come from a legitimate cloud service or trusted organization.

The email contains a device code and instructs the user to visit an authentic Microsoft verification page.

Because the website itself is legitimate, users often see no obvious signs of fraud.

Once the victim enters the code, the attacker captures the OAuth authentication token generated during the process. That token can then be used to access the victim’s Microsoft 365 account without requiring a password or additional authentication.

Why The Scam Is Difficult To Detect

One reason security experts are particularly concerned about Kali365 is that it removes many of the warning signs people have been taught to look for.

Traditional phishing attacks often rely on fake websites, suspicious URLs, or misspelled domain names. In a Kali365 attack, none of those indicators may exist.

Victims are directed to a genuine Microsoft verification page, making the request appear legitimate.

As a result, even security-conscious users may struggle to recognize the attack before it is too late.

Researchers reported hundreds of Kali365-related attacks within weeks of the platform’s emergence, suggesting that adoption among cybercriminals is accelerating rapidly.

Why Multifactor Authentication Alone May Not Be Enough

Multifactor authentication remains one of the most effective security measures available, but Kali365 demonstrates that it is not immune to exploitation.

Instead of defeating MFA directly, attackers trick users into authorizing access themselves through legitimate authentication workflows.

The result is that attackers obtain a valid access token that allows them to operate inside the account as if they were the authorized user.

This technique has become increasingly attractive to cybercriminals because it avoids triggering many traditional security alerts associated with password theft.

How Microsoft 365 Users Can Protect Themselves

The FBI advises users to be extremely cautious when receiving unexpected requests involving device codes or authentication prompts.

Users should:

  • Never enter a device code that they did not personally request
  • Verify unexpected authentication requests through trusted channels
  • Review active sessions and connected applications regularly
  • Enable additional account monitoring and security alerts
  • Report suspected phishing attempts immediately

Anyone who believes they may have been targeted by a Kali365 attack can also file a report through the FBI’s Internet Crime Complaint Center.

A New Era Of Phishing Threats

The rise of Kali365 reflects a broader evolution in cybercrime. Attackers are increasingly focusing on authentication tokens, session credentials, and authorization systems rather than traditional passwords.

For organizations and individuals alike, the lesson is becoming clear: cybersecurity is no longer just about protecting passwords. It is about protecting the entire authentication process.

As phishing kits become more automated and AI-driven, experts warn that attacks like Kali365 could become increasingly common, making user awareness and vigilance more important than ever.

Source: INC

Read more news, and follow us on Instagram

Photo: Getty Images

Share This Article
Email Copy Link Print
Previous Article Ukrainian entrepreneur in Dubai How Dubai Became the Launchpad for a Ukrainian Entrepreneur’s Success
Next Article Shivani Sharma millet innovation The Entrepreneur Turning Millets Into A Modern FMCG Opportunity

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
XFollow
InstagramFollow
LinkedInFollow
MediumFollow
QuoraFollow
- Advertisement -
Ad image

You Might Also Like

human skills in AI era LinkedIn 5Cs
Latest NewsTechnology

LinkedIn CEO Says These 5 Human Skills Matter More Than Ever in the Age of AI

By The Editorial Desk
Latest NewsWorld

Glimpse into the Spectacular Landscapes of World National Parks

By The Editorial Desk
Meta premium subscriptions
BusinessLatest NewsTechnology

Meta Plans Paid AI Subscriptions for Instagram, Facebook, and WhatsApp

By The Editorial Desk
Flipkart IPO governance
Latest NewsStartUpsWorld

Flipkart Strengthens Leadership and Supply Chain Ahead of IPO

By The Editorial Desk
The CEO register The CEO register

The CEO Register is a business and leadership publication reporting on CEOs, companies, and the decisions shaping enterprise.

Top Categories
  • Latest News
  • Business
  • World
  • Women
  • Entrepreneurs
  • Technology
  • Success Stories
Usefull Links
  • About Us
  • Contact Us
  • Advertise with Us
  • Privacy Policy
  • Submit a Tip
Social Media

© 2026 The CEO Register. All rights reserved.
A publication of Xoopic Media.

The CEO register The CEO register
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?