FBI Warns Microsoft 365 Users About Dangerous Kali365 Phising That Can Bypass MFA Without Your Password
- Utshab Biswas

- Jun 15
- 5 min read
A new FBI warning reveals that the Kali365 phishing toolkit can bypass Microsoft 365 multifactor authentication by exploiting OAuth device codes. Here's how the scam works and the steps users should take to protect their Outlook, Teams, and OneDrive accounts.

Over the years, multifactor authentication (MFA) has become synonymous with some of the most effective ways to protect oneself from cybercriminals. Millions of people have used MFA to make their accounts more secure under the impression that no matter how much effort it takes to find out your password, nothing will happen because of MFA.
However, there is a new warning from the FBI which states that the level of safety provided by multifactor authentication may be far less effective than most people think.
Also Read: iPhone 18 Pro Max Leaks Reveal Major Camera, AI and Battery Upgrades Ahead of September 2026 Launch
A new phishing attack scheme can be used against MFA and it exploits its weaknesses. The phishing attack affects Microsoft 365 products like Outlook, Teams, and OneDrive, and here comes the most terrifying part – no passwords are needed for this type of attack.
FBI Issues Warning Over Growing Kali365 Phising
The Federal Bureau of Investigation warned the public of a phishing scam that is using an easy-to-use hacking tool dubbed Kali365. Traditional phishing scams try to extract username and password data from victims through the use of a fake log-in page; however, the hackers behind Kali365 are interested in collecting something more sinister – authentication tokens.
Security experts say that the platform has been successfully exploited by scammers as early as April 2026 and is already associated with hundreds of attacks that target Microsoft 365 subscribers.
What sets this malware apart is its accessibility. According to Bitdefender, Kali365 is being marketed as a subscription service for cybercriminals. Hackers who want to use this platform can acquire a subscription for as little as $250 a month or approximately $2,000 yearly.
In effect, cyber criminals no longer need to be skilled in complex hacking techniques to conduct phishing scams successfully.
What Exactly Is Kali365?
The Kali365 malware takes advantage of the device authentication mechanism by Microsoft’s OAuth.
This is a mechanism that enables the safe authorizing of apps to access some of the user's data while ensuring no passwords need to be typed several times. OAuth is an extensively used tool aimed at providing additional convenience and security to users.
Nevertheless, the hackers found their own trick.
While other kinds of malicious programs target logins, Kali365 exploits device codes. They serve to provide users with easier access to their accounts when using gadgets with limited opportunities for typing passwords. While working normally, they ensure smooth operation of devices. But once the attacker gets hold of the obtained authentication token, the damage becomes almost impossible to fix. That is where the problems truly start.
How the Kali365 Scam Works
The process itself is rather straightforward; in part, it explains why this problem is so alarming for cybersecurity specialists.
Typically, the process begins with sending a phishing e-mail designed to mimic communications from a legitimate cloud provider or business-related source. In most cases, this communication creates an atmosphere of urgency and encourages users to act immediately. Upon opening the e-mail, victims are told to visit the Microsoft website and provide a specific device code. The first thing one might notice about such a scam is that everything seems legit.
There are no misspellings, there is no need to interact with poorly designed websites all red flags that users have gotten used to watching out for. That's exactly the problem, as all appearances of legitimacy turn out to be misleading.
In other words, once the device code is entered into the provided box, hackers get hold of the OAuth access token from the corresponding authentication session. In the end, there was no need to find out the victim's password; no further MFA verification codes needed to be obtained for accessing Microsoft 365 accounts.
What Attackers Can Access
Once inside, attackers can move freely across Microsoft's ecosystem.
They may gain access to:
Outlook emails and attachments.
Teams conversations and shared files.
OneDrive documents and stored data.
Contact lists and organizational information.
Internal communications.
Sensitive business records.
Since the token has already been verified by Microsoft’s systems, attackers can proceed in their operations as though they are actually valid users.
When it comes to organizations who rely heavily on Microsoft 365, the consequences are dire. Sensitive information from organizations, finances, strategy discussions, and even information about customers may all become available to attackers without any evidence that passwords have been broken.
AI Is Making Phishing More Convincing
Another worrying characteristic of Kali365 lies in its inclusion of artificial intelligence technology. The FBI claims that attackers will be able to use artificial intelligence for crafting phishing emails, as well as providing them with an automation tool for running email campaigns, real-time dashboards for tracking the process, and even a convenient way of capturing OAuth tokens.
This essentially means that phishing emails become more sophisticated. It is no longer possible to easily identify scam emails by noticing some grammar errors or unusual formatting. Nowadays, phishing emails can easily mimic actual emails sent by legitimate services.
According to another user who reacted to the FBI's statement, these scams only get better every day.
Why Multifactor Authentication Alone Isn't Enough
It should be noted that the caution from the FBI does not imply that the method is inefficient. On the contrary, multifactor authentication still proves to be among the key security solutions. However, according to Kali365, there is one thing about cyberattacks that is worth noting – today hackers go beyond stealing the credentials.
In case the attacker uses authenticated sessions and token-based authentication, it becomes difficult to apply standard approaches for security since the user grants access to an attacker on his own.
Therefore, nowadays users should be aware of this fact and develop an approach that goes beyond passwords and MFA.
How Microsoft 365 Users Can Protect Themselves
The FBI recommends several precautions to reduce the risk of falling victim to these attacks.
Never Enter Device Codes You Didn't Request
Whenever you get an e-mail directing you to check your identity through a Microsoft verification website using a device code, which is one you never requested yourself, be wary.
Normally, such authentications happen when the action originated from you.
Verify Requests Through Official Channels
Before completing any unexpected authentication process, confirm its legitimacy through trusted communication channels, especially in workplace environments.
Educate Employees and Family Members
Awareness remains one of the strongest defenses against phishing attacks. Ensure that everyone using Microsoft 365 understands how device code scams operate.
Monitor Account Activity
Regularly review recent sign-in activity and connected applications associated with your Microsoft account.
Unrecognized sessions or unusual access attempts should be investigated immediately.
Report Suspected Incidents
In case you suspect that you have become a victim of Kali365 hacking, report the incident to the Federal Bureau of Investigation through their Internet Crime Complaint Center, and inform your company’s IT department immediately.
It can be helpful during future investigations.
The emergence of Kali365 should remind us that attackers will always develop new techniques that leverage trust and convenience.
The current scam does not rely on password theft or redirection of victims to malicious websites. Instead, it turns the process of authenticating users into an attack vector itself.
For M365 account holders, the lesson here is clear: remain vigilant, consider any authentication prompts carefully, and keep in mind that even seemingly safe processes demand careful consideration.
MFA is vital, but so too is awareness in this age of evolving threats.
















Comments