The FBI has issued an urgent public warning about Kali365, a “phishing-as-a-service” scheme targeting Microsoft 365 users, including people who use Outlook, Teams, and OneDrive. Multiple outlets report that Kali365 does not rely on stealing usernames or passwords through a fake login page. Instead, it targets OAuth device codes—authorization codes that can be used during legitimate Microsoft sign-in flows. In the scam, victims receive phishing emails impersonating trusted cloud or document-sharing services and receive a device code with instructions to enter it on a real Microsoft verification page. After the victim submits the code, attackers obtain OAuth access and refresh tokens, giving them ongoing access to the victim’s Microsoft 365 account without needing a password and potentially without triggering additional multi-factor authentication prompts.

Reports also say the platform can lower the technical barrier for attackers by providing tools such as AI-generated phishing lures, automated campaign templates, and tracking features. The FBI’s warning notes the scheme was first seen in April 2026 and that the service has been promoted or distributed through Telegram. The FBI and cited sources advise users and organizations to restrict or block device code flow via conditional access policies and take related account-protection steps, with affected parties able to file complaints with the FBI’s Internet Crime Complaint Center (IC3).