
The newest way hackers hijack your Outlook, Teams, and OneDrive starts with a code you type into a real Microsoft page.
Story Snapshot
- Kali365 is a “phishing-as-a-service” kit that steals Microsoft 365 tokens, not passwords
- Attackers can slip past multi‑factor authentication and sit inside Outlook, Teams, and OneDrive unnoticed [2]
- The FBI says even low‑skill criminals can rent these tools by the month, like Netflix for hacking [2]
- One simple habit – how you treat surprise device codes – can kill most of these attacks [1]
Why The FBI Is Suddenly Shouting About Kali365
The Federal Bureau of Investigation (FBI) does not blast out public service announcements for every new tech scare. When it does, it usually means two things: the attack is real, and ordinary people are walking straight into it.
In May, the FBI’s Internet Crime Complaint Center warned about Kali365, a phishing‑as‑a‑service platform that lets criminals steal Microsoft 365 access tokens and bypass multi‑factor authentication without ever seeing your password.
That is the part that should make you sit up. If you assumed codes on your phone were the last line of defense, Kali365 is the rude wake‑up call.
Kali365 is sold like a software subscription, mostly advertised on the chat app Telegram and rented to scammers for a few hundred dollars a month [2][4].
Buyers do not need to be expert hackers. The kit gives them dashboards to track victims, canned phishing campaigns, and even artificial-intelligence-generated lures that look like real business emails.
That is the bigger story here: crime “platforms” keep lowering the skill bar until almost anyone willing to break the law can point‑and‑click their way into your work life.
How A Simple Device Code Opens Your Whole Microsoft World
The trick behind Kali365 is not magic. It is an abuse of a real Microsoft feature called “device code” sign‑in, which exists so you can log in on gadgets with no keyboard, like a smart TV [1]. Here is how the FBI says the scam plays out in the real world.
First, you receive an email that appears to come from a trusted cloud or document service — think Adobe Sign, DocuSign, or a shared SharePoint file [4]. The message feels routine and often uses a bit of fake urgency: “A document needs your attention” or “Click to review.”
FBI issues urgent Kali365 security warning for Teams, Outlook, OneDrive usershttps://t.co/J22HOHtP4C
— The Hill (@thehill) June 15, 2026
The email includes a short device code and directs you to a real Microsoft verification page to enter it. This is where many cautious users let their guard down. You check the address bar, you see the padlock, and you are on a genuine Microsoft site.
No sketchy spellings, no fake login screen. You type the code yourself and, if Microsoft asks, you pass your usual multi‑factor authentication challenge.
From your point of view, everything looks clean. But you have actually authorized the attacker’s application, not your own device. Behind the scenes, Microsoft hands over OAuth access and refresh tokens tied to your account.
Why Tokens Beat Your Password And MFA
Tokens are how Microsoft remembers you are signed in. They are like stamped wristbands at a concert: once you have one, security stops checking your ticket at every door. Kali365 goes after those wristbands instead of the ticket.
Once the attacker has valid access and refresh tokens, they can open Outlook, Teams, OneDrive, and other Microsoft 365 services as if they were you — without typing your password and without triggering another multi‑factor prompt [2]. Multi‑factor authentication did its job during sign‑in; the attacker simply rode along on your approved session [1].
This is why the conservative instinct to “trust but verify” matters online as much as it does in politics. Many people treat any login that shows a lock icon and an MFA prompt as safe by default. Kali365 shows that blind trust in big tech flows can be just as naive as trusting Washington to police itself.
The technique itself is not brand‑new — security pros have tracked token theft and device‑code abuse for years — but packaging it into a polished crime kit that anyone can rent is the dangerous twist. It turns advanced fraud into a commodity.
What Attackers Do Inside Your Outlook, Teams, And OneDrive
Once inside, attackers do not usually smash and grab; they lurk. With full Outlook access, they can quietly read email, reset passwords for other services, and watch how money and information move through your life or business [1][3].
In Teams, they can eavesdrop on chats, join meetings, and learn who to impersonate for maximum effect. In OneDrive and SharePoint, they can copy contracts, tax records, health files, or internal strategy decks, then leak or sell them later [1][4].
🚨 FBI WARNS MICROSOFT USERS ABOUT NEW KALI365 PHISHING SCAM.
The FBI is alerting Microsoft 365 users about a fast‑growing phishing‑as‑a‑service scam called Kali365. The tool helps attackers steal OAuth tokens and slip past multi‑factor authentication. It uses AI‑generated lures… pic.twitter.com/67AwdkqBdi
— The Content Factory (@tcf_updates) June 16, 2026
From there, the playbook often shifts to classic fraud. The same FBI alert and follow‑on research warn that Kali365 and similar kits support business email compromise, in which crooks spoof a boss or vendor to reroute wire transfers. This is where the impact lands squarely on families and small businesses, not just giant corporations.
When a scammer drains a local company’s operating account after weeks of silent inbox snooping, there is no tech bailout coming. Personal responsibility and basic cyber hygiene are the only safety net.
Simple Rules That Stop A Sophisticated Scam
The good news is that blocking Kali365 on your end does not require a computer science degree. The single most important habit is this: never enter a device code on a Microsoft verification page unless you started that sign‑in yourself, on your own device [1].
If an email hands you a code you did not request, treat it like a stranger asking for your house alarm PIN. Delete it or report it as phishing in Outlook using the built‑in “Report phishing” option. When in doubt, call your company’s tech staff or the known sender using a phone number you already trust.
For businesses, the FBI and security firms stress a few technical moves. First, turn off the device‑code sign‑in flow if your organization does not truly need it [1].
Second, use conditional access policies so only known devices and locations can connect, even with a valid token [1]. Finally, monitor for new or unusual device registrations and session activity; those are the footprints this scam leaves behind.
Those steps align with common sense: limit unnecessary features, tighten access to what you actually use, and assume that if a tool can be abused, someone will eventually abuse it.
Sources:
[1] Web – FBI issues urgent Kali365 security warning for Teams, Outlook, …
[2] Web – FBI warns of Kali365 phishing scam targeting Microsoft 365 users
[3] Web – FBI warns about PhaaS platform used to access Microsoft 365 …
[4] Web – FBI warns Microsoft Teams, Outlook, OneDrive users of phishing scam





























