# FBI warns Microsoft 365 users of Kali365 passwordless phishing scam

**Published:** 2026-06-29T19:39:25.422Z  
**Topic:** Microsoft  
**Sentiment:** neutral  
**Publisher:** TrendWatcher — https://www.trendwatcher.in/article/3b883f60-4bae-424e-8f31-0fa04353f42c

FBI alert (May 21 2026) flags Kali365 phishing‑as‑a‑service that steals OAuth tokens, exposing Outlook, Teams and OneDrive accounts to passwordless hijacks.

A new phishing‑as‑a‑service called **Kali365** was highlighted in an FBI alert on May 21 2026, showing how attackers can bypass password and MFA by stealing OAuth tokens that grant persistent access to Microsoft 365 services such as Outlook, Teams and OneDrive【1】.  

| At a glance | |
|---|---|
| Alert date | May 21 2026 |
| Platform targeted | Microsoft 365 (Outlook, OneDrive, Teams) |
| Scam name | Kali365 (first seen April 2026) |
| Attack method | OAuth token theft via device‑code flow |

## How the scam works  

The FBI describes a four‑step flow: a phishing email mimics a trusted Microsoft service and includes a device code; the victim follows a link to a legitimate Microsoft verification page and enters the code; this authorizes the attacker’s device, handing over OAuth access and refresh tokens; the attacker then retains unlimited, password‑less access to the victim’s account【1】. Because the tokens bypass multi‑factor authentication, the compromise can continue indefinitely unless the user revokes the tokens.  

## Scope and implications  

Microsoft 365 powers “hundreds of millions” of users and “millions of businesses worldwide,” including more than a million U.S. companies【1】. The FBI notes that Kali365 lowers the technical barrier, offering AI‑generated phishing lures and automated campaign tools for a subscription fee, enabling low‑skill actors to hijack email, cloud storage and collaboration tools【3】. The platform’s reliance on the device‑code flow means that disabling or restricting this authentication method can mitigate the risk, a recommendation the FBI includes in its advisory【1】.  

## What to watch  

- **Policy changes** – Microsoft may tighten default settings for device‑code flow or issue tighter conditional‑access guidance.  
- **Subscription uptake** – Monitoring the prevalence of Kali365 subscriptions on Telegram could signal the scale of the threat.  
- **Enterprise response** – Large organizations’ security teams may roll out broader token‑revocation sweeps or adopt stricter MFA enforcement.  

The emergence of Kali365 underscores a shift in credential‑theft tactics: rather than stealing passwords, attackers are targeting the underlying authentication tokens that keep users logged in. As the FBI’s alert shows, the effectiveness of this approach hinges on Microsoft’s ability to adapt its access‑control mechanisms and on users’ vigilance in monitoring token activity.

## Sources
1. AOL — [FBI warns Microsoft Outlook, OneDrive, Teams users of phishing scam](https://www.aol.com/news/fbi-warns-microsoft-outlook-onedrive-161447298.html)
2. KSBY News Santa Barbara-San Luis Obispo, CA on MSN — [FBI warns of phishing scam targeting Microsoft 365 users](https://www.msn.com/en-us/news/technology/fbi-warns-of-phishing-scam-targeting-microsoft-365-users/vi-AA260QKm?ocid=BingNewsVerp)
3. The News Tribune — [Weekly Scam Alert: The FBI Is Warning Microsoft Users About a Sneaky New Phishing Attack](https://www.thenewstribune.com/money/scam-alert-microsoft-365-phishing/)

---
Cite as: TrendWatcher, "FBI warns Microsoft 365 users of Kali365 passwordless phishing scam", https://www.trendwatcher.in/article/3b883f60-4bae-424e-8f31-0fa04353f42c
