06/02/2026
The FBI is warning Microsoft 365 users about Kali365, a new phishing service that can hijack accounts without stealing passwords. Because Microsoft 365 is widely used across businesses, schools, and government organizations, a compromised account could expose emails, Teams chats, OneDrive files, contracts, and other sensitive data.
Kali365, which was first observed in April, abuses legitimate Microsoft device authorization pages to grant persistent access to cybercriminal-controlled applications.