Skip to content
FBITechnologyCrime

FBI Warns Microsoft 365 Users About Emerging Kali365 Scam

According to the agency, Kali365 operates as a “Phishing-as-a-Service” platform that allows cybercriminals with limited technical expertise to launch sophisticated attacks against Microsoft account holders.

FBI issues urgent Kali365 security warning for Microsoft users. Pic via (@thehill)

The FBI has issued an urgent warning about a growing cyber threat targeting users of Microsoft 365 services, including Teams, Outlook, and OneDrive, through a phishing platform known as Kali365.

According to the agency, Kali365 operates as a “Phishing-as-a-Service” platform that allows cybercriminals with limited technical expertise to launch sophisticated attacks against Microsoft account holders.

The service is reportedly available through a subscription model, making advanced phishing tools more accessible to a broader range of threat actors.

💡
The scam relies on obtaining OAuth device codes, which can allow attackers to gain access to Microsoft accounts without needing a password. Victims typically receive phishing emails disguised as messages from trusted document-sharing services.

The emails contain instructions and device codes that, if entered by the recipient, can grant unauthorized access to their accounts and bypass certain authentication protections.

Federal investigators warn that the platform incorporates artificial intelligence tools to generate convincing phishing messages, automate campaigns, and track targets in real time.

These capabilities increase the likelihood that fraudulent communications will appear legitimate and successfully deceive users.

💡
The FBI advises individuals and organizations to remain cautious when receiving unsolicited requests involving verification codes or login approvals.

Users are encouraged to avoid clicking unfamiliar links, carefully verify requests for authentication credentials, monitor account activity for unauthorized access, and promptly report suspicious emails or login attempts.

Microsoft has also urged customers to follow federal guidance and noted that its security teams continue efforts to disrupt phishing operations and protect users from evolving cyber threats.

Related Tweet:

Also Read:

Microsoft, Nvidia Partner To Speed Up Nuclear Power Using AI
Microsoft and Nvidia have announced a joint push to accelerate nuclear power development using artificial intelligence, as reported from the CERAWeek conference in Houston. Microsoft Vice Chair Brad Smith said the initiative aims to remove long-standing bottlenecks in building nuclear plants, especially as AI systems demand more energy. The

Comments

Latest

A Requiem For Privacy

A Requiem For Privacy

Trump prefers to receive his briefings directly from the CIA and its foreign colleagues, leaving the DNI as an appendage with little to do.

Members Public