FBI Warns of Kali365 Phishing Service Targeting Microsoft 365 Accounts

The FBI has issued a warning about Kali365, a phishing-as-a-service platform capable of bypassing multi-factor authentication on Microsoft 365 accounts.

FBI Warns of Kali365 Phishing Service Targeting Microsoft 365 Accounts

FBI Flags Kali365 as Active Threat to Microsoft 365 Users

The FBI has issued a warning about a phishing-as-a-service platform known as Kali365, which is being used to target Microsoft 365 accounts, Google News MT reports.

The service is notable for its ability to bypass multi-factor authentication (MFA), a security layer many organisations rely on to protect user accounts. Kali365 operates as a ready-made criminal toolkit, allowing threat actors to launch credential-harvesting campaigns without advanced technical knowledge.

Security researchers at Help Net Security and The Hacker News have separately documented how similar services exploit OAuth consent flows to circumvent MFA protections. Rather than stealing passwords directly, attackers trick users into granting application-level access, effectively rendering standard authentication controls ineffective.

Australia's signals directorate, ASD, has also raised concerns about device code phishing, a technique tracked alongside Kali365 by cybersecurity firm Proofpoint as part of a broader rise in commercially available phishing toolkits.

Forbes reported that the attack method grants adversaries direct account access without requiring the victim's password to be exposed in the conventional sense.

Microsoft 365 account holders — particularly those in corporate environments — are advised by authorities to review third-party application permissions and monitor for unauthorised access attempts.

Source: Google News MT