05/28/2026
FBI Warns of New Attack That Lets Hackers Break Into Outlook, Teams, and OneDrive — Even With MFA Enabled
The FBI has issued an urgent alert about a fast‑growing cyberattack campaign targeting Microsoft 365 users. The threat, known as Kali365, is a Phishing‑as‑a‑Service platform that allows attackers to break into Outlook, Teams, OneDrive, and other Microsoft cloud services without needing passwords or MFA codes.
This attack is spreading quickly across businesses, schools, and government organizations — and it works by abusing a legitimate Microsoft authentication feature that most people don’t think twice about.
---
How the Attack Works
Kali365 doesn’t try to steal your password. Instead, attackers send a phishing email that looks like a document‑sharing request, voicemail notification, or cloud login prompt. The email includes a device code and instructs the user to enter it on a real Microsoft login page.
That’s the trick.
When the victim enters the code, they unknowingly approve the attacker’s device. The attacker instantly receives valid access tokens, giving them full access to the victim’s Microsoft 365 account — no password, no MFA challenge, no alerts.
Once inside, attackers can:
- Read and send email
- Access OneDrive files
- Join Teams chats
- Steal data or impersonate employees
- Move laterally to other systems
- Set up persistence for long‑term access
Because the login is authorized through Microsoft’s own device‑code flow, it looks legitimate in logs and is difficult for organizations to detect.
---
Why This Threat Is Growing Fast
Kali365 is sold as a subscription service on criminal marketplaces, complete with:
- Prebuilt phishing templates
- AI‑generated lures
- Dashboards showing real‑time victim activity
- Automated token harvesting
In other words, attackers don’t need technical skill — they just need a credit card and a Telegram account.
This is part of a broader trend: token‑based attacks are replacing password‑based attacks, and MFA alone is no longer enough.
---
What Organizations Should Do Now
The FBI recommends several immediate steps to reduce exposure:
1. Restrict or disable device‑code authentication
Most organizations don’t need it. If you do, limit it to specific apps or trusted devices.
2. Review Conditional Access policies
Block risky authentication flows and require compliant or managed devices.
3. Monitor for unusual token activity
Look for logins without corresponding MFA prompts or from unexpected locations.
4. Train users on device‑code phishing
Most people have never seen this attack before — which is exactly why it works.
5. Protect break‑glass accounts
Ensure emergency access accounts are excluded from broad restrictions to avoid accidental lockouts.
---
The Bigger Picture
Kali365 is a reminder that attackers are shifting away from stealing credentials and toward stealing trust — abusing legitimate authentication flows to bypass security controls.
For organizations, this means:
- MFA is necessary but not sufficient
- Token‑based attacks must be part of threat modeling
- Conditional Access is now a frontline defense
- User training must evolve beyond “don’t click suspicious links”
This is a moment for businesses to reassess how they secure Microsoft 365 and whether their controls match today’s threat landscape.
Get the latest Alabama local news, sports, weather, entertainment and breaking updates on al.com