06/16/2026
🚨 FBI Warning: New Kali365 Phishing Kit Bypassing MFA in Microsoft 365 🚨
The FBI just issued an urgent alert about Kali365 — a Phishing-as-a-Service platform that's making it easier for attackers to hijack Microsoft 365 accounts by stealing access tokens (not passwords).
How it works:
You receive a phishing email pretending to be from a trusted service.
It gives you a "device code" and tells you to go to the legitimate Microsoft login page and enter it.
By doing so, you unknowingly grant the attacker full access to your Outlook, Teams, OneDrive, and more — even with MFA enabled.
This is a growing threat, especially for businesses using Microsoft 365.
Protect yourself:
Block Device Code Authentication (via Conditional Access or Security Defaults)
Review sign-in logs regularly
Be extremely cautious with any unexpected "verification code" requests
Full FBI/IC3 Advisory:
https://www.ic3.gov/PSA/2026/PSA260521
If you manage IT or cybersecurity for your company (or clients), this is a must-act-now item. Share this with your team!