FBI warns Microsoft 365 users of new Kali365 phishing scam: What it is, how it works

The FBI has issued a warning regarding 'Kali365,' a new phishing-as-a-service platform that allows cybercriminals to bypass multi-factor authentication on Microsoft 365 accounts. The platform is sold via Telegram and enables attackers to steal OAuth tokens to gain persistent access to corporate and personal cloud services.
Why it matters
This represents a significant escalation in cybercrime, as it lowers the technical barrier for attackers to compromise widely used enterprise software.
FBI warns Microsoft 365 users of new Kali365 phishing scam: What it is, how it works
The article reports on an official government advisory and cybersecurity threat without editorializing.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in