{"id":237716,"date":"2026-05-26T02:16:06","date_gmt":"2026-05-26T07:16:06","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2026\/05\/fbi-warns-of-kali365-phishing-service-targeting-microsoft-365-accounts"},"modified":"2026-05-26T02:16:06","modified_gmt":"2026-05-26T07:16:06","slug":"fbi-warns-of-kali365-phishing-service-targeting-microsoft-365-accounts","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2026\/05\/fbi-warns-of-kali365-phishing-service-targeting-microsoft-365-accounts","title":{"rendered":"FBI warns of Kali365 phishing service targeting Microsoft 365 accounts"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/fbi-warns-of-kali365-phishing-service-targeting-microsoft-365-accounts.jpg\"><\/a><\/p>\n<p>The FBI is warning about the Kali365 phishing-as-a-service platform (PhaaS) that is used to hijack Microsoft 365 accounts by abusing OAuth device code authentication to steal session tokens and bypass multi-factor authentication (MFA).<\/p>\n<p>According to the <a href=\"https:\/\/www.ic3.gov\/PSA\/2026\/PSA260521\" target=\"_blank\" rel=\"nofollow noopener\">FBI PSA<\/a>, Kali365 first emerged in April 2026 and is distributed via Telegram channels for cybercriminals seeking an easier way to compromise Microsoft 365 accounts without stealing passwords or intercepting MFA codes.<\/p>\n<p>The platform uses device code phishing, an increasingly popular method that abuses <a href=\"http:\/\/learn.microsoft.com\/en-us\/entra\/identity-platform\/v2-oauth2-device-code\" target=\"_blank\" rel=\"nofollow noopener\">Microsoft\u2019s legitimate OAuth 2.0 Device Authorization grant flow<\/a> to gain access to Microsoft Entra and Microsoft 365 accounts.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The FBI is warning about the Kali365 phishing-as-a-service platform (PhaaS) that is used to hijack Microsoft 365 accounts by abusing OAuth device code authentication to steal session tokens and bypass multi-factor authentication (MFA). According to the FBI PSA, Kali365 first emerged in April 2026 and is distributed via Telegram channels for cybercriminals seeking an easier [\u2026]<\/p>\n","protected":false},"author":427,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34],"tags":[],"class_list":["post-237716","post","type-post","status-publish","format-standard","hentry","category-cybercrime-malcode"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/237716","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/427"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=237716"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/237716\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=237716"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=237716"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=237716"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}