- The FBI’s sounding the alarm on Kali365, a site where criminals can pick up ready-to-use tools for stealing Microsoft 365 accounts.
- Attackers send fake login prompts or document-sharing requests, tricking people into signing in. Even if you log in through the real Microsoft page, Kali365 grabs your digital access tokens, allowing crooks to skip your passwords and any extra security steps.
- It’s run like a subscription, too. For around $250 a month, even hackers without much technical skill get access to these sophisticated phishing tools.
A recent bulletin from the FBI has described an increasing number of scams targeting consumers who use Microsoft products and services.
The latest of these scams uses a program called Kali365. This program lets attackers illegally gain access to customer accounts associated with the following Microsoft applications: Outlook, Teams, and OneDrive.
Millions of users around the world access these products daily; therefore, they are prime targets for criminal activity designed to obtain users’ personal information.
What the FBI Is Warning People About
The FBI refers to Kali365 as a phishing-as-a-service platform; this means that scammers can buy tools to perform scams instead of creating them themselves from scratch. This Kali356 allows them to rent everything they require to generate false messages and access accounts for just about $250/month.
According to the FBI, they first noticed Kali365 in April 2026. Since then, they have seen it used against both companies and regular people.
Here is the thing about these attacks. The messages look real. They do not have obvious typos or weird formatting. Most of these emails advise you to verify your document or approve someone else’s access to a shared document which seems completely normal and quite boring.
How this Attack Works
The attack uses something called device code phishing. Microsoft built this functionality for devices without keyboards or web-based browsers. It’s designed so users can log in to smart TVs or other electronic devices; however, criminals figured out a way around this.
Here is how it plays out. The scammer sends an email with code and provides some instructions. The email could claim that a person shared a document with you or that your account requires verification, which will take you to the real Microsoft login page.
The sneaky part is that the login page is actually the true login page. You type in your password. Also, you approve the login on your phone. You think you are doing something normal and safe. But you just gave the criminals what they needed.
After you’ve logged in, Microsoft often issues you a digital token, which is more like a temporary key for you to gain access into your account without needing to input a password again. The attackers capture that key. Now they can get into your email, files, and messages without needing your password.
What About Multi-Factor Authentication?
Most people know that multi-factor authentication keeps accounts safe. You have probably used it yourself. It asks for a code from your phone or a fingerprint scan. It adds an extra step before someone can log in.
But Kali365 gets around that. The attackers are not trying to steal your password or verification code. They wait until you finish logging in. Then they take the token that Microsoft creates. That token is like a master key.
This is a smart way to attack. Criminals are not trying to break into systems anymore. They are tricking people into letting them in.
The FBI is also concerned about encryption making it harder to investigate such attacks. The FBI Director has called encryption a “dark hurdle,” showing the challenges law enforcement faces from multiple angles.
And it works because people trust the Microsoft login page. They do not realize they are handing over access. Microsoft supports the FBI’s warning. They have been fighting these kinds of scams for a while. Their Digital Crimes Unit has taken down other platforms like Kali365 in the past.
The company says they keep working to stop these criminal networks. They also tell users to be careful. Check your account activity. Look for unusual logins as well as unexpected requests to login.
Advice on Avoiding these Scams
Recently, the FBI issued open advice on how to reduce the chances that you will experience headaches from being a victim of cybercrime. The biggest rule of thumb is to never ever enter a verification code via an email unless you requested that verification code yourself. Ignore unexpected messages or those from unknown sources.
Also, be cautious. If a message sounds urgent or demands that you perform an action immediately. Stop and think for a minute. Scammers often create a sense of urgency so that you won’t have time to consider if the message is real before clicking a link. They want you to skip thinking and just click.
Check your Microsoft account from time to time. Check the devices that have accessed your account and the locations from where they have accessed it. If anything feels off, change your passwords immediately.
Spot any phishing attempt? Report it. By doing this, you are assisting the FBI in locating and stopping the individuals who are committing such scams.
Why this Matters
This Kali365 thing shows us something bigger happening in cybercrime. As technology advances, the cost of purchasing scamming tools is getting cheaper and carrying out complex attacks gets easier too.
Just like you can rent tools at a hardware store, criminals can rent scamming tools online. The subscription model makes it easy. Anyone with some cash can get started. That means more attacks and more people getting hurt.
The FBI has made it clear that safety these days takes more than just slapping on strong passwords. Attackers are wiser now. always finding creative ways to steal from you.
Keeping yourself safe doesn’t require a computer science degree, just simple habits and a bit of caution. Slow down. Question unexpected requests.
Check your account activity. These simple habits can stop most attacks. The criminals count on you being in a hurry. Do not give them that chance.
Share this article
About the Author
Farwa is an experienced InfoSec writer and cybersecurity journalist skilled in writing articles related to cybersecurity, AI, DevOps, Big Data, Cloud security, VPNs, IAM, and Cloud Computing. Also a contributor on Tripwire.com, Infosecurity Magazine, Security Boulevard, DevOps.com, and CPO Magazine.
More from Farwa SajjadRelated Posts
Google and FBI Disrupt NetNut Residential Proxy Network Used by 2M+ Devices
Google worked with the FBI and Lumen to disrupt the NetNut residential proxy network, also known as ...
Opera Launches Paste Protect to Block ClickFix Clipboard Attacks
Opera’s Paste Protect blocks harmful commands from reaching the clipboard, preventing ClickFix...
Reddit Introduces Mandatory Age Verification for EU Teens Accessing NSFW Content
Reddit will require European Union users under 18 to verify their age before viewing mature or NSFW ...
Popular ‘Adblock for YouTube’ Chrome Extension Found With Remote Code Execution Risk
The popular “Adblock for YouTube” Chrome extension now carries an architectural weakness...
Texas Hunting and Fishing License Data Breach Affects 3 Million Customers
Approximately 3 million Texas hunting and fishing license customers were affected by a data breach i...
Cybercriminal Claims Leak of Internal Visa Systems, but No Customer Data Exposed
A cybercriminal claims they have internal Visa system details, including authentication flows and AP...