FBI Warns of ‘Kali365’ Cyber Threat Targeting Microsoft 365 Users Through Telegram-Based Phishing Service

kali 365
The FBI has issued a warning over Kali365, a Telegram-based phishing platform targeting Microsoft 365 users by bypassing multi-factor authentication and stealing account access tokens.

Washington, D.C. | June 16, 2026: The Federal Bureau of Investigation (FBI) has issued a public alert regarding a rapidly emerging cyber threat known as “Kali365,” a phishing-as-a-service platform reportedly targeting Microsoft 365 users through sophisticated scams distributed on Telegram.
According to cybersecurity reports, Kali365 is designed to help cybercriminals gain unauthorized access to Microsoft 365 accounts by exploiting a legitimate authentication process rather than stealing passwords directly. The platform reportedly enables attackers to bypass multi-factor authentication (MFA), a widely trusted security feature used to protect online accounts.
First detected in April 2026, Kali365 has been circulating through Telegram channels and is being marketed as an easy-to-use toolkit, allowing even low-skilled cybercriminals to launch advanced phishing attacks. Security agencies have warned that the service includes automated phishing templates, AI-generated scam messages, real-time victim tracking systems, and tools capable of capturing Microsoft OAuth access tokens.

Unlike traditional phishing attacks that rely on stealing usernames and passwords, Kali365 reportedly manipulates Microsoft’s device authentication process. Victims are often tricked into entering a code on a legitimate Microsoft page, unknowingly granting attackers access to services such as Outlook, Teams, and OneDrive without realizing their accounts have been compromised.
Cybersecurity experts believe the growing accessibility of phishing-as-a-service platforms marks a concerning shift in online fraud, lowering the technical barrier for cybercrime and increasing risks for businesses and individuals alike. The FBI has urged Microsoft 365 users and organisations to remain cautious about suspicious emails, unexpected login requests, and unfamiliar authentication prompts.
Social media Handles :
Instagram
Youtube
Facebook
Twitter
Also Read- Pune