The FBI has issued an urgent public security warning about a fast-spreading phishing scam targeting Microsoft 365 users, including those using Teams, Outlook and OneDrive. The FBI says the hacking platform Kali365 is designed to seek “OAuth device codes,” which can let scammers bypass multi-factor authentication without obtaining a user’s password. According to the reporting, Kali365 focuses on capturing Microsoft authentication tokens associated with OAuth, enabling attackers to gain access to Microsoft accounts and navigate related services.
The scam typically starts with a phishing email that appears to come from a trusted cloud service and includes instructions that direct the recipient to enter a device code on what is described as a legitimate Microsoft verification page. When the code is entered, attackers reportedly capture the OAuth access token, allowing them to access the victim’s Microsoft 365 account. The reporting also notes that the approach can be difficult to spot because it does not rely on a clearly fake website or obvious domain misspellings.
The FBI advises users not to open links or enter access codes that they did not request and says affected victims can file complaints with the Internet Crime Complaint Center.