×
Cyber Security

FBI Warns Businesses About New Microsoft 365 Phishing Threat: What You Need to Know About Kali365

By Annie Slovensky ยท
Masked figure at a laptop in a dark room representing a phishing attacker

The FBI recently issued a public warning about a sophisticated phishing platform known as Kali365, which is being used to compromise Microsoft 365 accounts while bypassing traditional multi-factor authentication (MFA) protections.

What Is Kali365?

Kali365 is a phishing-as-a-service platform that lets attackers reach Microsoft 365 accounts by abusing legitimate authentication workflows.

How the Attack Works

A typical Kali365 attack follows these steps:

  • A victim receives an email, text, or chat request.
  • They are prompted to enter a device authentication code.
  • The attacker captures the resulting session.

How Businesses Can Protect Themselves

Review Microsoft 365 Security Settings

Tighten conditional access and block legacy authentication.

Invest in Cybersecurity Awareness Training

Most breaches still start with a person clicking something.