Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Mark Angel’s New Marriage Sets Social Media Ablaze as Fans Revisit Ex-Wife’s Shocking Claims

    June 2, 2026

    Arsenal Fan Dies After Collapsing During Champions League Final Viewing in Anambra

    June 1, 2026

    50 Cent Reacts to Viral Online Controversy Involving Daphne Joy and Diddy

    June 1, 2026
    Facebook X (Twitter) Instagram YouTube LinkedIn WhatsApp TikTok Telegram
    Naijabizfinder
    • Home
    • Politics
    • Business
    • Technology
    • Entertainment
    • Environment
    • Health
    • Lifestyle
    • Sports
    • Technology
    • Travel
    • World
    Facebook X (Twitter) Instagram
    Subscribe
    Trending Topics:
    • Home
    • Politics
    • Business
    • Technology
    • Entertainment
    • Environment
    • Health
    • Lifestyle
    • Sports
    • Technology
    • Travel
    • World
    Naijabizfinder
    • Home
    • Politics
    • Business
    • Technology
    • Entertainment
    • Environment
    • Health
    • Lifestyle
    • Sports
    • Technology
    • Travel
    • World
    Home » FBI Warns Kali365 Hack Can Breach Microsoft 365 Accounts Without Passwords or MFA
    Technology

    FBI Raises Red Alert Over ‘Kali365’ Hack: Cybercriminals Can Now Breach Microsoft 365 Accounts Without Passwords or MFA Codes

    New phishing platform exploits Microsoft’s own login system, giving hackers stealth access to Outlook, Teams, OneDrive, and corporate networks worldwide.
    SholaBy SholaJune 1, 2026Updated:June 1, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp VKontakte Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Federal Bureau of Investigation (FBI) has issued an urgent cybersecurity warning over a rapidly emerging hacking platform known as Kali365, a sophisticated phishing service that enables cybercriminals to gain access to Microsoft 365 accounts without stealing passwords or bypassing traditional multi-factor authentication (MFA) protections.

    The warning comes amid growing concern among cybersecurity experts, who say the platform represents a dangerous evolution in cybercrime by exploiting Microsoft’s legitimate authentication infrastructure rather than attacking it directly.

    According to the FBI, Kali365 operates as a “phishing-as-a-service” platform, allowing even low-skilled cybercriminals to launch highly effective attacks against businesses, government agencies, schools, healthcare providers, and other organizations that rely on Microsoft 365 services.

    Unlike conventional phishing schemes that attempt to trick users into revealing passwords, Kali365 abuses Microsoft’s device code authentication process — a legitimate feature commonly used to log in on smart TVs, gaming consoles, and other devices with limited keyboards or input options.

    Victims are typically sent convincing emails disguised as notifications from trusted Microsoft services such as SharePoint, OneDrive, Teams, or Outlook. The messages instruct recipients to enter a device verification code on an authentic Microsoft login page.

    Because users are interacting with a genuine Microsoft website, many security-conscious individuals fail to recognize the attack.

    Once the victim enters the code and completes the MFA verification process, the attacker receives valid OAuth authentication tokens that provide ongoing access to the user’s Microsoft 365 environment. With those tokens, cybercriminals can access emails, files, calendars, cloud storage, and collaboration platforms without needing the victim’s password.

    Security experts warn that these access tokens can remain active for extended periods and may continue to function until they are manually revoked by administrators or account owners.

    The FBI described Kali365 as a significant threat because it lowers the barriers to entry for cybercriminals by providing ready-made attack tools, automated phishing workflows, AI-generated scam messages, and real-time dashboards that allow attackers to monitor victims as they fall into the trap.

    Cybersecurity analysts say the attack is particularly effective because it exploits trust in Microsoft’s own systems. Traditional security products often focus on detecting fake websites, credential theft, or malware, while Kali365 leverages legitimate authentication processes that appear normal to both users and security software.

    Matt Burk, Chief Information Security Officer at Bespoke Concierge MD, said the technique was specifically designed to undermine one of the strongest defenses currently used by organizations worldwide.

    “Since Microsoft has globally enforced MFA, this method of cyber attack is designed to bypass MFA and the need for a password,” Burk explained.

    The platform reportedly surfaced in underground cybercrime communities in May 2026 and has quickly gained popularity on hacker forums and encrypted messaging channels. Security firms monitoring the threat have already observed campaigns targeting hundreds of organizations across North America, Europe, Australia, and other regions.

    Industries reportedly affected include healthcare, education, manufacturing, financial services, government institutions, and critical infrastructure operators.

    The FBI is now urging organizations to strengthen their security posture by educating employees about device-code phishing scams, monitoring suspicious authentication requests, reviewing OAuth permissions, enforcing stricter session controls, and immediately revoking suspicious access tokens when detected.

    Cybersecurity experts warn that the rise of platforms like Kali365 signals a major shift in the threat landscape, where attackers increasingly target identity systems instead of passwords. As businesses continue to migrate critical operations to cloud-based platforms, protecting user identities and authentication processes has become as important as protecting networks themselves.

    With Microsoft 365 serving millions of organizations worldwide, authorities caution that the threat posed by Kali365 is likely to grow rapidly unless companies take proactive steps to detect and block these emerging attacks.

    Reference: FBI Cybersecurity Advisory; findings from cybersecurity firms monitoring Kali365 phishing campaigns, including reported observations from organizations affected across the United States, Canada, Europe, and Australia.

    Business Security Cloud Security Cybercrime Cybersecurity News Data Breach FBI Cyber Alert Kali365 MFA Bypass Microsoft 365 Hack Microsoft Teams Security OAuth Token Theft OneDrive Hack Outlook Security Phishing Attack Technology News
    Share. Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Email
    Previous Article31-Year-Old South African Woman “Turns into Old Lady” After One-Night Stand with Foreigner? Fact Check Reveals the Truth
    Next Article 50 Cent Reacts to Viral Online Controversy Involving Daphne Joy and Diddy
    Shola
    • Website

    Related Posts

    Nigerian Reviewer Gets Keys to Burna Boy’s £2M McLaren Senna – And the Internet Is Losing It!

    May 29, 2026

    NASA Engineers Reveal ‘Invisible Bass Cannon’ That Could Stop Wildfires Before They Reach Homes

    May 22, 2026
    Leave A Reply Cancel Reply

    Demo
    Our Picks
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    Entertainment

    Mark Angel’s New Marriage Sets Social Media Ablaze as Fans Revisit Ex-Wife’s Shocking Claims

    By SholaJune 2, 20260

    Nigerian comedian and content creator Mark Angel is once again making headlines after reportedly remarrying…

    Arsenal Fan Dies After Collapsing During Champions League Final Viewing in Anambra

    June 1, 2026

    50 Cent Reacts to Viral Online Controversy Involving Daphne Joy and Diddy

    June 1, 2026

    FBI Raises Red Alert Over ‘Kali365’ Hack: Cybercriminals Can Now Breach Microsoft 365 Accounts Without Passwords or MFA Codes

    June 1, 2026

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Your source for the lifestyle news. This demo is crafted specifically to exhibit the use of the theme as a lifestyle site. Visit our main page for more demos.

    We're accepting new partnerships right now.

    Email Us: info@example.com
    Contact: +1-320-0123-451

    Our Picks
    New Comments
      Facebook X (Twitter) Instagram Pinterest
      © 2026 ThemeSphere. Designed by ThemeSphere.

      Type above and press Enter to search. Press Esc to cancel.

      Powered by
      ►
      Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
      None
      ►
      Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
      None
      ►
      Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
      None
      ►
      Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
      None
      ►
      Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
      None
      Powered by