05/31/2026
🚨 FBI Warning: A new phishing threat called Kali365 is targeting Microsoft 365 users by exploiting legitimate Microsoft login processes to bypass traditional security measures.
Unlike typical phishing attacks, cybercriminals don’t need your password. By tricking users into entering a device verification code on a real Microsoft page, attackers can gain ongoing access to Outlook, Teams, OneDrive, and other Microsoft 365 services.
🔒 What can you do?
✅ Be cautious of unexpected emails requesting authentication codes.
✅ Verify requests through trusted channels.
✅ Review and strengthen Microsoft 365 security policies.
✅ Monitor for unusual login activity and unauthorized devices.
Cyber threats continue to evolve, making user awareness and proactive security more important than ever.
If your organization needs help assessing Microsoft 365 security risks or strengthening your cybersecurity posture, KCI Technology Solutions can help.
🌐 Reach out to us at KCI Technology Solutions
A new phishing tool is allowing cyber attackers to get access to Microsoft 365 users’ accounts without even needing to know your password, the FBI said in a warning issued to the public on Th…