If you use Microsoft 365 for email, Teams, or OneDrive, there’s a new threat you should know about.
In May 2026 the FBI issued a public warning about a phishing-as-a-service platform called Kali365. This tool is designed to give attackers access to Microsoft 365 accounts in a way that often bypasses the multi-factor authentication (MFA) many of us rely on.
Unlike traditional phishing that tries to steal your password, Kali365 focuses on stealing something called access tokens. Once an attacker has those tokens, they can get into your Outlook, Teams, and OneDrive and stay there, even if you change your password later.
This matters for local businesses because so many of us depend on Microsoft 365 every day. A successful attack can lead to stolen emails, fraudulent invoices sent from your account, or sensitive files being accessed without anyone noticing right away.
Kali365 is a ready-made service sold mainly through Telegram. Attackers can subscribe to it (reports put the price around a few hundred dollars per month) and get access to:
It lowers the skill level needed to run these attacks. Someone with limited technical knowledge can still launch a polished campaign.
The platform first appeared in April 2026 and has been actively used against Microsoft 365 users ever since.
The most common version of this attack uses something called a device code. Here’s the simple version of what happens:
In some cases the platform also uses more advanced techniques that sit between you and the real Microsoft login page, but the end result is the same: the attacker ends up with valid access.
Most people feel safer knowing they have multi-factor authentication turned on. Kali365 is designed to work around that protection. Because the victim completes the login on Microsoft’s own site, the system treats the session as legitimate.
Once inside, attackers can:
For a small business, the damage can add up quickly.
Be especially careful when you see any of these:
Remember: you should only enter a device code when you initiated the process on a device you control (for example, signing into a new computer or a conference room system).
Here are practical steps every local business should consider:
For every user
For your Microsoft 365 environment (these usually require an administrator)
These changes are best handled carefully. Blocking the wrong setting can disrupt day-to-day work, so it helps to have someone who knows your specific Microsoft 365 setup.
At TimbukTech we spend a lot of time helping local companies keep their technology simple and secure. Threats like Kali365 are a good reminder that security is not just about strong passwords. It is also about understanding how modern attacks work and putting the right guardrails in place.
If you would like us to review your Microsoft 365 settings, check for the device code flow, or walk through current best practices, we are happy to help. We keep the conversation straightforward and focused on what actually matters for your business.
You should not have to become a cybersecurity expert just to run your company. That is why we are here.
Stay alert, question unexpected requests for codes, and reach out if you have questions. We are always glad to talk through it with you.