Observed Signal · May 28, 2026 · Security Advisory · Source: t3n · Impact: 3/5 · Sentiment: Negative

FBI warns Microsoft 365 users about Kali365 phishing

Executive Signal Summary

The U.S. FBI has issued a public advisory warning Microsoft 365 users about a new phishing platform called Kali365. First observed in April and reported to circulate mainly on Telegram, Kali365 provides Phishing-as-a-Service tooling that helps attackers harvest OAuth access and refresh tokens via a device-code phishing flow. According to the FBI, criminals can use those tokens to bypass passwords and multi-factor authentication and access Microsoft 365 services such as Outlook, Teams and OneDrive. The FBI recommends restricting or disabling OAuth device-code flows except where absolutely necessary and following other hardening measures to reduce exposure.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

A government security advisory highlights a new PhaaS that captures OAuth tokens and can bypass MFA for Microsoft 365 — a meaningful identity/security risk for many organizations and SaaS platforms.

SIGNAL RADAR

Track Microsoft Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • FBI issued a public advisory warning about the Kali365 phishing platform targeting Microsoft 365 users.
  • Kali365 was first observed by the FBI in April and is circulated notably via Telegram.
  • The platform facilitates Phishing-as-a-Service (PhaaS) that harvests OAuth access and refresh tokens through a device-code flow.
  • Attackers using stolen tokens can access Microsoft 365 services (Outlook, Teams, OneDrive) without passwords or MFA checks.
  • The FBI recommends restricting the OAuth device-code flow and blocking unnecessary device-code token issuance.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: t3n•Published: May 28, 2026
Original Coverage Title: “Neue Phishing-Plattform: FBI warnt Nutzer von Outlook, Teams und Onedrive”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

IdentityJul 28, 2026

Public Wi‑Fi DNS Poisoning Hijacks Microsoft 365 Sessions

Security researchers report a campaign that compromises public Wi‑Fi gateway management interfaces (e.g., in hotels, conference centers) to forge DNS responses and WPAD proxy settings, redirecting users to fake Microsoft sign‑in pages. Attackers exploit the OAuth device‑code flow (Microsoft Entra ID) and WPAD to obtain MFA‑authenticated tokens and access Microsoft 365 sessions without installing malware on victims' devices. Activity has been observed since June 2026 in the US, India, and Saudi Arabia. Detection techniques include monitoring for IOC IPs/domains, PAC/WPAD downloads (WinHttpAutoProxySvc), device‑code sign‑ins, and unusual post‑MFA access from unknown IPs/locations. Primary coverage cites SecurityWeek and a detailed ReliaQuest threat spotlight as sources.

Read assessment
IdentityAug 13, 2026

Microsoft warns against SMS-based 2FA over AI phishing

Microsoft has warned IT administrators that SMS- and voice-based two-factor authentication (2FA) are increasingly vulnerable due to AI-assisted phishing and easier SIM-swapping. In an internal email, the company recommended migrating to phishing-resistant methods such as passkeys. Microsoft said it has observed a strong rise in AI-driven attacks with higher click-through rates that aim to capture passwords and MFA codes. As a consequence, Microsoft will disable SMS- and voice-based authentication for Entra ID accounts starting February 1, 2027; a timeline for personal Microsoft accounts has not yet been announced.

Read assessment
Platform SecurityApr 1, 2026

LinkedIn Malware Warning: Security Advice for Employers and Jobseekers

The article warns LinkedIn users—both employers and jobseekers—to treat messages with caution, even from known contacts that may be compromised. It recommends verifying job opportunities outside LinkedIn, avoiding any job offers that require downloading or executing files, and recognising that familiar services (e.g., Google, Dropbox) or trusted domains do not guarantee safety. Users should regularly review and terminate unfamiliar active sessions in LinkedIn settings and treat distant or anomalous logins as signs of account compromise. The piece advises enabling multi-factor authentication (ideally using hardware security keys) and notes LinkedIn supports software passkeys. If compromise is suspected, users should reset passwords and revoke all sessions.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.