www.infosecurity-magazine.com 5/25/2026, 9:59:04 AM · external

FBI alerts on Kali365 AI phishing stealing Microsoft 365 tokens

FBI alerts on Kali365 AI phishing stealing Microsoft 365 tokens
CyberSIXT Evidence Panel
Primary Source ic3.gov

THE FBI has issued a warning about a new phishing-as-a-service platform called Kali365, discovered in April 2026, which primarily operates on Telegram. This tool allows cybercriminals to use AI-generated phishing methods to capture Microsoft 365 OAuth tokens, enabling them to bypass multifactor authentication. The attack involves sending a phishing email that misleads victims into authorizing access to their Microsoft accounts without realizing it. To combat these attacks, the FBI suggests implementing conditional access policies and restricting device code flows.

View Primary Source Via www.infosecurity-magazine.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline