Email Phishing

Security Alert: Kali365 Microsoft 365 Phishing Threat

If you use Microsoft 365 for email, Teams, or OneDrive, there’s a new threat you should know about.

In May 2026 the FBI issued a public warning about a phishing-as-a-service platform called Kali365. This tool is designed to give attackers access to Microsoft 365 accounts in a way that often bypasses the multi-factor authentication (MFA) many of us rely on.

Unlike traditional phishing that tries to steal your password, Kali365 focuses on stealing something called access tokens. Once an attacker has those tokens, they can get into your Outlook, Teams, and OneDrive and stay there, even if you change your password later.

This matters for local businesses because so many of us depend on Microsoft 365 every day. A successful attack can lead to stolen emails, fraudulent invoices sent from your account, or sensitive files being accessed without anyone noticing right away.

What Exactly Is Kali365?

Kali365 is a ready-made service sold mainly through Telegram. Attackers can subscribe to it (reports put the price around a few hundred dollars per month) and get access to:

  • AI-generated phishing emails that look convincing
  • Pre-built campaign templates
  • Tools that capture Microsoft access tokens
  • Dashboards to track their victims

It lowers the skill level needed to run these attacks. Someone with limited technical knowledge can still launch a polished campaign.

The platform first appeared in April 2026 and has been actively used against Microsoft 365 users ever since.

How the Attack Works (Step by Step)

The most common version of this attack uses something called a device code. Here’s the simple version of what happens:

  1. The lure You receive an email that looks like it comes from a familiar service (a document sharing request, a Teams invite, a shared file notification, etc.). The email includes a short code and tells you to visit Microsoft’s real verification page and enter that code.
  2. The authorization Because the page is a genuine Microsoft website, everything looks legitimate. You paste in the code, complete any MFA prompt, and think you’ve just opened a shared document or joined a meeting.
  3. Token theft By entering that code, you have actually authorized the attacker’s device to access your account. The attacker quietly captures the access and refresh tokens Microsoft issues.
  4. Persistent access With those tokens in hand, the attacker can now open Outlook, Teams, and OneDrive as if they were you. They usually do not need your password again and do not trigger another MFA challenge.

In some cases the platform also uses more advanced techniques that sit between you and the real Microsoft login page, but the end result is the same: the attacker ends up with valid access.

Why This Threat Feels Different

Most people feel safer knowing they have multi-factor authentication turned on. Kali365 is designed to work around that protection. Because the victim completes the login on Microsoft’s own site, the system treats the session as legitimate.

Once inside, attackers can:

  • Read and send email from your account
  • Access files in OneDrive or SharePoint
  • Create inbox rules that hide security alerts
  • Impersonate you when contacting customers, vendors, or employees

For a small business, the damage can add up quickly.

Red Flags to Watch For

Be especially careful when you see any of these:

  • An unexpected email asking you to enter a Microsoft device code
  • A message claiming you need to “verify” or “view a shared document” by visiting a Microsoft page and typing a code
  • Pressure or urgency (“This document expires in 24 hours”)
  • A code that arrives through email, text, or Teams when you did not start a sign-in yourself

Remember: you should only enter a device code when you initiated the process on a device you control (for example, signing into a new computer or a conference room system).

How to Protect Your Business

Here are practical steps every local business should consider:

For every user

  • Never enter a Microsoft device code that arrives in an unexpected email or message.
  • If you need to sign into a new device, go directly to Microsoft’s website yourself instead of clicking links in emails.
  • Regularly review the devices and sessions listed under your Microsoft account. Remove anything you do not recognize.
  • Keep multi-factor authentication turned on. It still blocks many other attacks.

For your Microsoft 365 environment (these usually require an administrator)

  • Restrict or block the “device code flow” through Conditional Access policies. This is the single most effective technical control recommended by the FBI.
  • Audit current device code usage first so you do not accidentally lock out legitimate systems (such as certain meeting room devices).
  • Block authentication transfer policies that allow sessions to move between devices.
  • Review recent sign-in activity and OAuth app permissions for anything unusual.
  • Consider moving high-risk users (owners, finance, and admins) to stronger, phishing-resistant methods such as hardware security keys or passkeys when possible.

These changes are best handled carefully. Blocking the wrong setting can disrupt day-to-day work, so it helps to have someone who knows your specific Microsoft 365 setup.

Peace of Mind for Central Illinois Businesses

At TimbukTech we spend a lot of time helping local companies keep their technology simple and secure. Threats like Kali365 are a good reminder that security is not just about strong passwords. It is also about understanding how modern attacks work and putting the right guardrails in place.

If you would like us to review your Microsoft 365 settings, check for the device code flow, or walk through current best practices, we are happy to help. We keep the conversation straightforward and focused on what actually matters for your business.

You should not have to become a cybersecurity expert just to run your company. That is why we are here.

Stay alert, question unexpected requests for codes, and reach out if you have questions. We are always glad to talk through it with you.