The FBI Issues Urgent Warning for Microsoft Teams, Outlook, and OneDrive Users Over Emerging Phishing Threat

Micrososft Apps

A rapidly evolving cybercrime operation known as Kali365 is enabling even inexperienced scammers to take over user accounts—without ever needing to steal a password.

The security layer millions depend on every day may not be as untouchable as many assume.

The Federal Bureau of Investigation (FBI) has issued an urgent alert regarding a sophisticated phishing campaign targeting users of Microsoft 365 services, including Outlook, Teams, and OneDrive. According to the warning, attackers are exploiting a method that captures Microsoft authentication tokens, allowing them to bypass multifactor authentication (MFA) entirely—without requiring account credentials.

At the center of the operation is a phishing platform called Kali365.

Unlike conventional phishing attacks that focus on harvesting usernames and passwords, Kali365 exploits OAuth device codes—temporary authorization keys that allow applications to access user data without repeated password entry. By abusing this process, cybercriminals can gain direct access to Microsoft 365 accounts and potentially expose large amounts of sensitive information.

The subscription-based toolkit, first identified in April 2026, has reportedly been marketed primarily through Telegram channels and, according to cybersecurity company Bitdefender, can be obtained by threat actors for as little as $250 per month or $2,000 annually.

What makes this campaign especially concerning is its accessibility.

According to the FBI, Kali365 significantly lowers the technical barrier for cybercriminals by providing built-in AI-generated phishing content, automated campaign deployment tools, real-time tracking dashboards for selected targets, and advanced OAuth token interception capabilities.

Security researchers reported hundreds of attempted Kali365 campaigns in April alone, indicating that the threat is already moving from theory into active exploitation.

How the attack works

The attack unfolds through a surprisingly convincing sequence of events.

Victims receive a phishing email carefully designed to resemble a legitimate communication from a trusted cloud provider. Inside the message is a device verification code along with instructions directing the recipient to a real Microsoft verification page.

Once the victim enters the code, the compromise begins instantly.

At that moment, the attacker captures the OAuth access token and gains access to the victim’s Microsoft 365 environment. This can include Outlook emails, Teams conversations, and files stored in OneDrive—without triggering additional password requests or authentication prompts.

One of the most deceptive aspects of the attack is that users are not redirected to a fake website and are not confronted with suspicious-looking domains.

Because the interaction occurs through legitimate Microsoft pages, distinguishing a malicious request from a genuine one becomes significantly more difficult.

As one user commented following the FBI alert :

“This phishing scam is becoming increasingly sophisticated, combining AI-generated lures with automated attack templates.”

However, the FBI advises that users can take several precautions to reduce their risk, including avoiding opening links containing access codes unless they specifically requested them. In addition, individuals who believe they have been impacted by the Kali365 phishing kit are encouraged to submit a report to the Internet Crime Complaint Center.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top