FBI IC3 PSA: Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokens
The Federal Bureau of Investigation ( FBI ) is issuing this Public Service Announcement ( PSA ) to warn the public an emerging Phishing 1 -as-a-Service 2 ( PhaaS ) platform called Kali365, first seen in April 2026. Kali365 has primarily been distributed via Telegram, enabling cyber threat actors to obtain Microsoft 365 access tokens and bypass multi-factor authentication 3 ( MFA ) protocols without intercepting the user's credentials.
Through the Kali365 platform subscription, cyber threat actors can capture "OAuth" tokens and gain persistent access to targeted individuals/entities' Microsoft 365 environments. Kali365 lowers the barrier of entry, providing less-technical attackers access to AI-generated phishing lures, automated campaign templates, real-time targeted individual/entity tracking dashboards, and OAuth token capture capabilities.
Restricting device code flow to limit or block device authentication codes can help prevent or limit this style of attack.
If you or someone you know has been impacted by the Kali365 Phishing kit, file a complaint with the Internet Crime Complaint Center ( IC3 ) at . Be sure to include any available information, such as:
Please see the Cybersecurity & Infrastructure Security Agency's ( CISA ) Phishing Guidance: Stopping the Attack Cycle at Phase One, which provides best practices and mitigations to protect against phishing techniques.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
