← Intelligence Center
Intelligence Center
Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokens
CVEs
None identified.
Products
- •Microsoft 365 (accounts and access tokens)
Executive Summary
The FBI issued a Public Service Announcement warning the public about an emerging Phishing-as-a-Service (PhaaS) platform called Kali365, first seen in April 2026. Kali365 has primarily been distributed via Telegram, enabling cyber threat actors to obtain Microsoft 365 access tokens and bypass multi-factor authentication (MFA) protocols without intercepting the user's credentials.
Municipal Impact
Municipalities using Microsoft 365 should be alert to this PhaaS threat and reinforce MFA and token security practices.
SMB Impact
SMBs heavily reliant on Microsoft 365 should review the FBI PSA and strengthen protections around access tokens and MFA.
Recommended Actions
- Review the FBI Public Service Announcement on Kali365.
- Remain vigilant for phishing attempts leveraging Microsoft 365 access token theft.
- Reinforce multi-factor authentication and monitor for anomalous token usage.
Grey Matter Analysis
Analysis pending review.
Get Help
Need help with this advisory?
Contact Grey Matter to assess your exposure and prioritize remediation.
Contact Grey Matter