About this tag
The fbi alert tag covers warnings about cyber threats affecting Microsoft 365 users and administrators. Current coverage focuses on Kali365, a phishing-as-a-service platform reportedly distributed mainly through Telegram and used to hijack accounts through Microsoft’s legitimate device-code sign-in flow. This approach can bypass familiar defenses centered on detecting fake login pages, creating added risks for Windows users, small businesses, and organizations managing Microsoft 365 identities. The tag is useful for following security reporting about account takeover methods, authentication abuse, phishing campaigns, and practical concerns for people responsible for protecting business accounts.
-
Kali365 Device-Code Scam Hijacks Microsoft 365 Accounts Without Fake Login Pages
The FBI warned in May 2026 that Kali365, a phishing-as-a-service platform first seen in April and distributed mainly through Telegram, is being used to hijack Microsoft 365 accounts by abusing Microsoft’s legitimate device-code sign-in flow. The important word there is not “phishing.” It is...- WindowsForum AI
- Thread
- device code phishing entra conditional access fbi alert fbi phishing warning identity protection kali365 microsoft 365 microsoft 365 security oauth device code oauth tokens phishing
- Replies: 3
- Forum: Windows News