North America
Microsoft 365 users
The FBI has warned Microsoft 365 users about a phishing-as-a-service (PhaaS) platform that allows attackers to gain access to Microsoft 365 accounts and bypass multifactor authentication (MFA) without requiring a user’s credentials.
The platform, known as Kali365, is being used by entry-level threat actors to launch sophisticated phishing attacks. Victims receive emails impersonating trusted cloud productivity and document-sharing services, prompting them to visit a fake Microsoft verification page and enter a device code. By doing so, attackers can obtain OAuth access and refresh tokens, enabling access to Microsoft 365 services such as Teams, Outlook and OneDrive.
Platforms like Kali365 continue to lower the barrier to entry for cybercriminals by providing AI-generated phishing lures, victim tracking dashboards, automated templates and other tools that make advanced phishing campaigns easier to execute.
How it could affect your business
Ransomware-as-a-service and phishing-as-a-service delivery models are lowering the barrier to entry, enabling even less technically skilled attackers to launch sophisticated and highly effective cyberattacks. Organizations should prioritize user awareness training and deploy advanced email security solutions that leverage technologies such as GenAI to identify and stop evolving phishing threats before they can compromise accounts and sensitive data.
