Story perspectives
FBI Flags Kali365 Phishing Service Targeting Microsoft 365
6/28/2026
1 of 1
Story summary
- The FBI warned that Kali365, a phishing-as-a-service platform seen in April 2026, is targeting Microsoft 365 accounts on Telegram.
- Scammers send cloud-service emails requesting an unexpected Microsoft device code, which steals OAuth tokens and opens Outlook, Teams and OneDrive without password or MFA.
- The FBI advises never entering unsolicited codes, revoking suspicious sign-ins, keeping MFA on, and when compromised signing out, changing passwords, reporting to IC3.gov and notifying IT.
