Clear reporting on the stories that matter
DP
Daily Pulse · June 28, 2026
Tech

FBI Warns Microsoft 365 Users of Passwordless Phishing Scam Bypassing Multi-Factor Authentication

A new phishing-as-a-service platform, Kali365, is exploiting Microsoft 365 accounts by leveraging legitimate device code login processes, enabling access without password theft.

FBI Warns Microsoft 365 Users of Passwordless Phishing Scam Bypassing Multi-Factor Authentication

A critical security vulnerability, often trusted by many for digital protection, may not be as robust as commonly perceived. The Federal Bureau of Investigation (FBI) has issued an alert concerning an emerging phishing-as-a-service platform known as Kali365, which specifically targets Microsoft 365 accounts, encompassing services like Outlook, Teams, and OneDrive.

What makes this threat particularly concerning is its operational method. This sophisticated scam can infiltrate user accounts without directly stealing passwords. Even with multi-factor authentication (MFA) enabled, an unwitting approval of a device code could grant unauthorized access to a malicious actor.

Understanding the Kali365 Attack Mechanism

OAuth tokens function as digital access keys, allowing applications to maintain a connection to a Microsoft account without requiring a password for every interaction. While beneficial for legitimate applications, these tokens become a significant risk when compromised by scammers.

Unlike most phishing attempts that aim to extract passwords, Kali365 employs a different strategy. The attack exploits Microsoft's legitimate device code login procedure. Users might recognize a similar process when signing into a streaming application on a smart television, where a short code is displayed on screen and then entered on another device to authorize the sign-in.

The initial login process itself is authentic. The scam commences when a criminal initiates a sign-in from their own device and manipulates the victim into approving it. This typically begins with a deceptive phishing email, crafted to appear as if it originates from a reputable cloud service or document-sharing platform. The message includes a device code and directs the recipient to a genuine Microsoft verification page.

The authenticity of the Microsoft verification page is a key element of this deceptive tactic. The web address may appear correct, password managers might not flag it, and the page could instill a false sense of security. However, upon entering the provided code, the victim inadvertently authorizes the attacker's device. This action allows the attacker to capture access and refresh tokens, thereby gaining entry to Outlook, Teams, and OneDrive without requiring the victim's password or triggering another MFA prompt.

This type of scam poses a risk to any individual or organization utilizing Microsoft 365. Small businesses, however, should be especially vigilant. Consider the sensitive information typically housed within a professional account: email correspondence, invoices, shared files, internal chats, vendor contacts, customer specifics, and calendar invitations. A single compromised account can provide a criminal with a highly credible persona to exploit.

An attacker who gains access to an Outlook account, for instance, can analyze communication patterns, send messages from the genuine account, and potentially instruct colleagues to process fraudulent invoices, share confidential files, or reset passwords. This scenario is alarming because the attack may no longer resemble a conventional scam; it could appear to originate from a known and trusted contact.

The FBI outlines the scheme in a clear sequence:

  • First, the victim receives a phishing email disguised as communication from a trusted productivity or file-sharing service.
  • Next, the email contains a device code and instructs the victim to input it on a legitimate Microsoft verification page.
  • Then, the victim enters the code, unknowingly granting approval to the attacker's device.
  • Following this, the attacker captures OAuth access and refresh tokens.
  • Finally, the attacker can access Microsoft 365 services such as Outlook, Teams, and OneDrive without needing the victim's password.

Protecting Your Microsoft Account

The most significant indicator of this scam is an unexpected request to enter a Microsoft device code. Users should be suspicious if an email prompts them to enter a code for a file, voicemail, invoice, or shared document that they did not initiate or request.

Additionally, be wary of messages that convey a sense of urgency. Scammers frequently use tactics that pressure recipients to act quickly, such as claims that a document will expire, a voicemail is pending, or an account requires immediate verification.

Context is another crucial clue. If you were not actively attempting to sign in to a device, do not enter a device code. Adopting this single habit can effectively prevent the scam from progressing.

Microsoft has advised customers to adhere to the FBI's recommendations, along with Microsoft's own published best practices, to defend against Kali365 and similar fraudulent schemes. The company also stated its ongoing efforts to disrupt cybercriminal operations linked to phishing-as-a-service and account takeover activities, citing recent actions by its Digital Crimes Unit against entities like Fake ONNX, RaccoonO365, and Tycoon 2FA as examples of these broader initiatives.

Adopting a few prudent habits can help individuals identify fraudulent device code requests, minimize their exposure, and align with the FBI’s guidance for mitigating this type of attack:

  • Only enter a Microsoft device code when you have personally initiated the sign-in process. If the code arrives via an unexpected email, Teams message, or a random document link, immediately halt the process.
  • Avoid using links embedded within unsolicited messages. Instead, open your web browser and navigate directly to Microsoft's official website or your company's Microsoft 365 portal.
  • Regularly review recent sign-ins, connected devices, and active sessions within your account. If you identify an unrecognized location, device, or application, take immediate action.
  • If you suspect you have mistakenly entered a fraudulent code, sign out of all active sessions and revoke access for any suspicious applications. Subsequently, change your password and notify your IT department.

It is crucial not to disable multi-factor authentication due to this scam. MFA remains an effective barrier against numerous account attacks. This particular threat underscores the necessity for users to exercise caution with approval prompts and device codes, even when MFA is active.

Recommendations for Organizations and Reporting Incidents

Employees may be aware of the risks of entering passwords on suspicious web pages, but many may not have received specific warnings about device codes. Integrating information about this particular scam into security training programs is highly advisable.

The FBI suggests that restricting device code flow can help prevent or limit this attack vector. IT teams should consider implementing a conditional access policy to block device code flow for all users, with limited exceptions for essential business processes.

Before imposing restrictions on device code flow, the FBI advises auditing current usage to identify legitimate business requirements. This proactive step can help prevent disruptions for employees or systems that depend on this sign-in method.

The FBI also recommends blocking authentication transfer policies, which can help prevent users from transferring authentication from desktop computers to mobile devices.

If an organization cannot fully restrict device code flow, the FBI suggests excluding emergency access accounts to avoid potential lockouts. This measure should be carefully managed by the organization's IT or security team.

If you or your organization has been targeted or compromised, it is imperative to report the incident to the FBI's Internet Crime Complaint Center at IC3.gov. When reporting, include comprehensive details such as phishing emails, email headers, suspicious login times, IP addresses, locations, unauthorized devices, and active sessions. Prompt action is critical.

This scam is particularly deceptive because it leverages a legitimate Microsoft sign-in page to facilitate criminal activity, making Kali365 a significant threat. It transforms a trusted security procedure into a potential trap, especially when the device code originates from an uninitiated source. The key takeaway is to exercise caution before entering any Microsoft device code. If a code appears unexpectedly via email, text, or Teams message, pause and navigate directly to your account portal instead. Never approve a sign-in unless you deliberately initiated it. A few extra moments of vigilance can be instrumental in safeguarding Outlook, Teams, OneDrive, and all associated information from unauthorized access.

FBI warningMicrosoft 365Kali365phishing scammulti-factor authentication bypassdevice code logincybersecurityOAuth tokens

The latest