Written By Divya
Published By: Divya | Published: Jun 16, 2026, 07:46 PM (IST)
Think your Microsoft 365 account is safe because you use two-factor authentication? A new phishing scam suggests that may not always be enough. Also Read: Microsoft reportedly considering Xbox spin-off: What it means for Fallout, Halo and The Elder Scrolls
A cybercrime platform called Kali365 is reportedly being used to target Microsoft 365 users worldwide, including businesses, professionals and enterprises that rely on Outlook, Teams and OneDrive. This comes after the threat has recently come to the attention of the FBI, which issued a warning about the scam’s ability to bypass certain security protections. Also Read: Meta confirms over 20,000 Instagram accounts hacked through AI recovery tool flaw: ALL details
According to the reports, Kali365 is said to be what cybersecurity experts call a “Phishing-as-a-Service” platform. In simple terms, it is a ready-made toolkit that allows cybercriminals to launch phishing attacks without needing advanced technical skills. Also Read: Xbox Series X gets a translucent green limited edition model for Xbox's 25th anniversary
The platform reportedly offers automated phishing campaigns, AI-generated email lures and tools that help attackers track potential victims. According to reports, the service is even being advertised through Telegram channels and is available through a subscription model. What makes Kali365 different is that it focuses on stealing authentication tokens instead of passwords.
The phishing email is designed to look like it comes from a reliable service, however. It might appear to be an invoice, meeting request, document sharing request, or file access request. The email has a code for customers to verify their identify on the official Microsoft login page. To the user’s eye everything seems to be alright as users are taken to a real Microsoft website and not a fake login page.
This is where the magic happens. What the victim types in is actually sending information to the attacker’s session. When the user has authenticated, Microsoft sends access tokens to the attacker rather than the victim’s device.
What happens after that? Cybercriminals can access Microsoft 365 services without ever needing the user’s password once again.
For years, users were told to look out for fake websites, suspicious links and spelling mistakes. Kali365 removes many of those red flags. The login page is genuine. The authentication process is genuine. Even multi-factor authentication works exactly as intended. The problem is that users are unknowingly approving access for someone else.
That makes these attacks harder to identify compared to traditional phishing scams.
And what if you have already been affected? Then you should immediately review active sessions, revoke suspicious device access and change account credentials. Also, make sure to file online complaint as soon as possible.