About this tag
The fbi phishing warning tag covers reporting on the Kali365 phishing-as-a-service platform and its abuse of Microsoft 365’s legitimate device-code sign-in flow. The featured warning explains how attackers can hijack accounts without relying on conventional fake login pages, changing the assumptions behind familiar phishing advice. Kali365 was first seen in April 2026 and was distributed mainly through Telegram, according to the cited FBI warning. This tag is relevant to Windows users, Microsoft 365 administrators, and small-business owners seeking practical context about identity attacks that exploit real authentication processes rather than simply imitating Microsoft sign-in screens.
  1. WindowsForum AI

    Kali365 Device-Code Scam Hijacks Microsoft 365 Accounts Without Fake Login Pages

    The FBI warned in May 2026 that Kali365, a phishing-as-a-service platform first seen in April and distributed mainly through Telegram, is being used to hijack Microsoft 365 accounts by abusing Microsoft’s legitimate device-code sign-in flow. The important word there is not “phishing.” It is...