Close Menu
The Financial News 247The Financial News 247
  • Home
  • News
  • Business
  • Finance
  • Companies
  • Investing
  • Markets
  • Lifestyle
  • Tech
  • More
    • Opinion
    • Climate
    • Web Stories
    • Spotlight
    • Press Release
What's On
Wednesday, July 22 Clues And Answers

Wednesday, July 22 Clues And Answers

July 21, 2026
What It Takes To Justify The Check

What It Takes To Justify The Check

July 21, 2026
Casino in Primm to reopen Wednesday just 17 days after Terrible’s takeover

Casino in Primm to reopen Wednesday just 17 days after Terrible’s takeover

July 21, 2026
American Open-Source Labs Think They Can Beat China’s Best AI Startups

American Open-Source Labs Think They Can Beat China’s Best AI Startups

July 21, 2026
Bill Gates’ Foundation Had No Ties To Epstein’s Crimes, Its External Probe Finds

Bill Gates’ Foundation Had No Ties To Epstein’s Crimes, Its External Probe Finds

July 21, 2026
Facebook X (Twitter) Instagram
The Financial News 247The Financial News 247
Demo
  • Home
  • News
  • Business
  • Finance
  • Companies
  • Investing
  • Markets
  • Lifestyle
  • Tech
  • More
    • Opinion
    • Climate
    • Web Stories
    • Spotlight
    • Press Release
The Financial News 247The Financial News 247
Home » FBI sounds alarm on phishing tool that steals Microsoft 365 accounts

FBI sounds alarm on phishing tool that steals Microsoft 365 accounts

By News RoomMay 28, 2026No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn WhatsApp Telegram Reddit Email Tumblr
FBI sounds alarm on phishing tool that steals Microsoft 365 accounts
Share
Facebook Twitter LinkedIn Pinterest Email

The FBI is warning that a new hacking platform is allowing cybercriminals to hijack Microsoft 365 accounts — including Outlook, Teams and OneDrive — while bypassing multi-factor authentication entirely.

The bureau posted a public service announcement last week sounding the alarm about the “Phishing-as-a-Service” toolkit known as Kali365, which is being used to steal Microsoft 365 access tokens and gain entry to victim accounts without intercepting passwords.

The feds say that Kali365 makes it easy for even amateur hackers to run advanced phishing scams that used to require serious technical skills.

The FBI is warning that cybercriminals are using a new phishing platform called Kali365 to hijack Microsoft 365 accounts and bypass multi-factor authentication.

“Kali365 lowers the barrier of entry, providing less-technical attackers access to AI-generated phishing lures, automated campaign templates, real-time targeted individual/entity tracking dashboards, and OAuth token capture capabilities,” the FBI warned.

The scheme exploits Microsoft’s legitimate OAuth 2.0 “device code” authentication system — a feature commonly used to log into smart TVs, streaming devices and other hardware with limited keyboards.

Rather than stealing passwords directly, attackers trick victims into entering a code on a real Microsoft login page, unknowingly authorizing the hacker’s device.

“The device code flow is a legitimate authentication method that is being actively exploited by cybercriminals to bypass multi-factor authentication,” the FBI said in its advisory.

“By tricking users into entering a device code on a legitimate Microsoft page, attackers can gain persistent access to accounts without ever needing the user’s credentials.”

Victims receive phishing emails impersonating services like SharePoint, OneDrive or Microsoft Teams.

Attackers using the Kali365 phishing toolkit can gain long-term access to Outlook, Teams and OneDrive accounts.

The emails instruct targets to visit Microsoft’s legitimate device login page and enter a short-lived authentication code.

Once the victim completes the process and passes MFA checks, Microsoft issues valid OAuth access and refresh tokens directly to the attacker.

That allows hackers to access Outlook inboxes, Teams accounts and cloud-stored files without ever needing the victim’s password again.

The FBI warned that attackers can maintain persistent access to accounts until the stolen tokens are manually revoked.

Matt Burk, chief information security officer at Bespoke Concierge MD, told The Post the attacks have become increasingly effective because Microsoft’s widespread enforcement of multi-factor authentication has forced cybercriminals to adapt.

Federal investigators warned that victims are being tricked into authorizing hackers through legitimate Microsoft device-login pages.

“Since Microsoft has globally enforced MFA, this method of cyber attack is designed to bypass MFA and the need for a password,” he said.

Asked which industries or employees are most vulnerable, Burk warned that virtually anyone using Microsoft 365 could be targeted.

“I absolutely hate to generalize, but everyone from a small mom-and-pop business to a large Fortune 500 company,” he said.

Burk added that organizations should deploy third-party Security Information and Event Management, or SIEM, systems capable of detecting suspicious authentication activity tied to token theft.

“Using these tools can detect access like the Kali365 exploit and with the correct security features can automatically shut down the connection,” he said.

Ordinary users should take the threat seriously because the attacks target cloud-based computing platforms used daily by businesses and consumers alike, according to the expert.

“Everybody should be concerned with this exploit,” Burk said.

Cybersecurity researchers say the emergence of Kali365 marks a major escalation in the growing “phishing-as-a-service” underground economy, where sophisticated attack tools are sold to low-skilled criminals via subscription services on Telegram and dark web forums.

The bureau said Kali365 was first observed last month and has rapidly spread among cybercriminal groups.

The platform automates phishing campaigns and provides dashboards that allow attackers to monitor victims in real time.

Federal authorities said the operation is part of a broader wave of attacks targeting Microsoft 365 environments globally.

Scattered Spider, also known as Octo Tempest, is a notorious English-speaking cybercrime group known for aggressive social engineering and SIM-swapping attacks targeting large corporations.

Another entity, Storm-2949, has focused on compromising IT administrators and senior executives through abuse of Microsoft password reset systems and cloud authentication tools.

The Post has sought comment from Microsoft.

Business cybersecurity FBI hack hackers Tech
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related News

Casino in Primm to reopen Wednesday just 17 days after Terrible’s takeover

Casino in Primm to reopen Wednesday just 17 days after Terrible’s takeover

July 21, 2026
China-based Moonshot AI seeks  billion valuation, could go public this year: report

China-based Moonshot AI seeks $50 billion valuation, could go public this year: report

July 21, 2026
Fox News star makes major announcement about his personal life

Fox News star makes major announcement about his personal life

July 21, 2026
College students get first payout in 4M financial aid price-fixing settlement

College students get first payout in $284M financial aid price-fixing settlement

July 21, 2026
WABC-TV’s ‘Eyewitness News’ announces major shakeup in its roster of reporters

WABC-TV’s ‘Eyewitness News’ announces major shakeup in its roster of reporters

July 21, 2026
San Francisco shifts focus from grocery store tax to access incentive

San Francisco shifts focus from grocery store tax to access incentive

July 21, 2026
Add A Comment
Leave A Reply Cancel Reply

Don't Miss
What It Takes To Justify The Check

What It Takes To Justify The Check

News July 21, 2026

FIFA has already shown one way it may sell World Cup 2030: bundle it with…

Casino in Primm to reopen Wednesday just 17 days after Terrible’s takeover

Casino in Primm to reopen Wednesday just 17 days after Terrible’s takeover

July 21, 2026
American Open-Source Labs Think They Can Beat China’s Best AI Startups

American Open-Source Labs Think They Can Beat China’s Best AI Startups

July 21, 2026
Bill Gates’ Foundation Had No Ties To Epstein’s Crimes, Its External Probe Finds

Bill Gates’ Foundation Had No Ties To Epstein’s Crimes, Its External Probe Finds

July 21, 2026
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Our Picks
China-based Moonshot AI seeks  billion valuation, could go public this year: report

China-based Moonshot AI seeks $50 billion valuation, could go public this year: report

July 21, 2026
The Single Best Tip For Pal Catching In ‘Palworld’

The Single Best Tip For Pal Catching In ‘Palworld’

July 21, 2026
How Netflix’s ‘The Hawk’ Reviews Stack Up Against Will Ferrell’s Movies

How Netflix’s ‘The Hawk’ Reviews Stack Up Against Will Ferrell’s Movies

July 21, 2026
Fox News star makes major announcement about his personal life

Fox News star makes major announcement about his personal life

July 21, 2026
The Financial News 247
Facebook X (Twitter) Instagram Pinterest
  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact us
© 2026 The Financial 247. All Rights Reserved.

Type above and press Enter to search. Press Esc to cancel.