Drooid Logo
Back to story perspectives

Full Breakdown

FBI Warns of Kali365 Phishing-as-a-Service Exploiting Microsoft 365 Device Code Flow

6/28/2026, 9:13:49 PM

Kali365 Phishing-as-a-Service Targets Microsoft 365 Accounts

The Federal Bureau of Investigation (FBI) has issued an advisory about Kali365, a phishing-as-a-service platform targeting Microsoft 365 users. The service provides subscribers with pre-configured phishing messages, campaign dashboards and tools to capture OAuth access and refresh tokens. These tokens enable attackers to access Outlook, Teams, OneDrive and other Microsoft 365 services without the victim’s password or an additional MFA prompt.

How the Device Code Flow Is Exploited

Microsoft’s device code flow enables sign-in on devices without browsers by showing a short code that the user enters on a Microsoft page. Approval issues an OAuth token that grants the requesting app ongoing access without a password. Kali365 sends phishing emails that mimic storage services and direct recipients to a sign-in page requesting a device code. Entering the code transfers the OAuth token to the attacker, allowing account access despite active MFA.

Key Actors and Official Responses

The warning originates from the FBI’s Internet Crime Complaint Center. Microsoft has reiterated its security guidance, urged customers to follow the FBI’s recommendations, and noted ongoing work by its Digital Crimes Unit to disrupt phishing-as-a-service operations such as Fake ONNX, RaccoonO365 and Tycoon 2FA. Commentary is provided by Kurt, known as CyberGuy, a media personality.

Impact on Businesses and Users

A compromised Microsoft 365 account can expose email threads, invoices, vendor contacts and customer data. Attackers can impersonate the account holder, send fraudulent payment requests, share malicious files or reset passwords. Small businesses, often reliant on a single shared account, face heightened exposure due to limited security resources.

Criticism & Opposition

Analysts note that multifactor authentication mitigates password-based attacks but does not prevent token-based compromises that exploit authentication flows. Critics argue that Microsoft’s support for device-code flow creates an attack surface that requires policy controls, such as conditional-access restrictions, rather than reliance on MFA alone.

Verbatim Quotes

  • “The FBI is warning about an emerging phishing-as-a-service platform called Kali365.” — FBI advisory
  • “Red flags to watch for The biggest warning sign is an unexpected request to enter a Microsoft device code.” — FBI advisory
  • “Kurt's key takeaways This is the kind of scam that can fool smart people because it uses a real Microsoft sign-in page to pull off something criminal.” — Kurt, CyberGuy
  • “9) Restrict device code flow if your business does not need it The FBI says restricting device code flow can help prevent or limit this style of attack.” — FBI advisory

What’s Next: Mitigation Recommendations

Users should ignore unsolicited device-code prompts and sign in via Microsoft’s official portal. Organizations should audit device-code usage, apply conditional-access policies that block the flow for non-essential users, review sign-in activity, revoke suspicious sessions, and report incidents to the FBI’s Internet Crime Complaint Center (IC3). Employee training on device-code scams is also advised.