Skip to content
Microsoft 365 Users Targeted by New Phishing Threat that Bypasses MFA

Microsoft 365 Users Targeted by New Phishing Threat that Bypasses MFA

Ground.News • May 22, 2026

The FBI has issued a public service announcement warning a new phishing kit that's stealing Microsoft OAuth tokens at an alarming rate. OAuth token theft is a serious headache for organizations because stolen tokens can bypass multi-factor authentication (MFA) and grant access to privileged accounts within an organization without needing to know their credentials. Think corporate espionage, data theft, maybe even ransomware. The main culpr…

Kali365 is targeting Microsoft 365 users through device code phishing, using OAuth token theft and Telegram-based distribution.

The U.S. Federal Bureau of Investigation (FBI) has issued a Public Service Announcement (Alert I-052126-PSA) warning a newly identified Phishing-as-a-Service (PhaaS) platform named Kali365, which is actively targeting Microsoft 365 users. First observed in April 2026, the platform enables attackers to bypass multi-factor authentication (MFA) by exploiting OAuth-based authentication flows. Kali365 PhaaS Platform Targets Microsoft […] The po…

To view factuality data please Upgrade to Premium

To view ownership data please Upgrade to Vantage

Extracted Entities

Attack Types (1)

MITRE ATT&CK (1)

Platforms (2)

Tools (1)