The FBI released a PSA warning the public about Kali365—an emerging Phishing-as-a-Service (PhaaS) platform.
Kali365, first seen in April 2026, enables cyber threat actors to obtain Microsoft 365 access tokens and bypass multi-factor authentication (MFA) protocols without intercepting the user’s credentials.
The platform allows less-skilled attackers access to AI-generated phishing lures, automated campaign templates, real-time targeted individual/entity tracking dashboards, and OAuth token capture capabilities.
Learn more about how the scam works and review recommendations on how to protect yourself: https://www.ic3.gov/PSA/2026/PSA260521
👉 In simple terms: Kali365 is a new "phishing-as-a-service" tool hackers can buy on Telegram. It lets even low-skill attackers send convincing emails pretending to be from Microsoft or a doc-sharing service.
👉The email gives you a code + link to the real Microsoft login page. You enter the code (thinking you're just approving something), but it secretly hands the attacker an "access token" to your Microsoft 365 account (email, Teams, OneDrive, etc.). They bypass your password and MFA after that.
👉Basically, it tricks you into giving them a master key to your work/school account without stealing your creds.
👉 Stay safe: Never enter a random code or approve a sign-in from an email. If you didn't start the login yourself, don't do it. Go straight to account.microsoft.com to check for weird activity.