A new MFA phishing attack tool is making headlines inside the FBI’s threat intelligence unit. On May 21, 2026, the agency issued a public service announcement warning businesses about Kali365 — a phishing-as-a-service platform sold on Telegram for as little as $250 per month that executes a tool so surgically it bypasses Microsoft 365’s multi-factor authentication entirely. Attackers gain persistent access to Outlook, Teams, and OneDrive without ever stealing a password.
The warning matters because most small businesses believe enabling MFA is enough. It is not — at least not against this class of attack. Understanding how Kali365 works, and what to do about it, is now a practical business necessity.
What Is Kali365?
Kali365 is a phishing-as-a-service (PhaaS) platform first observed in April 2026. Like a software subscription for cybercriminals, it packages all the infrastructure needed to launch sophisticated campaigns against Microsoft 365 accounts — no technical expertise required. According to Help Net Security, Kali365 has already been linked to attacks on hundreds of organizations, and its low price point lowers the barrier dramatically for would-be attackers.
Small businesses running email marketing software and cloud-based CRM tools are squarely in the crosshairs. Microsoft 365 accounts often hold the keys to customer data, financial records, and internal communications — exactly the targets that make the attack worth executing.

How an MFA Phishing Attack Using Device Codes Works
Kali365 uses device code phishing — a technique that exploits a legitimate Microsoft authentication flow designed for keyboard-less devices like smart TVs and printers.
The attack follows a precise sequence:
- Attackers send emails impersonating cloud services or document-sharing platforms, embedding a device code with instructions directing the recipient to Microsoft’s official verification page at microsoft.com/devicelogin.
- Because the destination is a genuine Microsoft URL, it bypasses URL-filtering tools and looks legitimate to employees.
- When the victim enters the code, they are not surrendering their password. They are authorizing the attacker’s device to access their account.
- The attacker captures OAuth access and refresh tokens — credentials that grant persistent, long-term access to the victim’s Microsoft 365 environment.
According to TechTimes, this token theft gives attackers ongoing access even after the victim changes their password — because tokens remain valid until explicitly revoked. That makes a Kali365 breach harder to remediate than a conventional credential theft.
Why Standard MFA Isn’t Enough Against This Threat
This is the uncomfortable reality Kali365 forces into focus: having MFA enabled does not protect against a device code MFA phishing attack.
Traditional MFA — SMS codes or authenticator app tokens — requires the attacker to intercept a time-limited one-time password. Device code phishing sidesteps this model entirely. There is no password prompt. The victim interacts with a real Microsoft page. The MFA challenge never fires in a way that blocks the attacker, because the authorization is granted through the device code itself.
Microsoft’s own research underscores the scale of the problem. The company’s Q1 2026 email threat report recorded 8.3 billion phishing attempts in a single quarter. A separate Microsoft security disclosure from April 2026 revealed a campaign targeting more than 35,000 users across 13,000 organizations in 26 countries — using fake HR and compliance emails to harvest tokens through adversary-in-the-middle (AiTM) techniques closely related to Kali365’s method.
For small businesses managing customer data through a CRM platform or running client communications through Microsoft 365, a compromised account is not merely an IT incident — it is a business continuity and data liability event.
6 Proven Steps to Stop an MFA Phishing Attack
- Upgrade to phishing-resistant MFA. FIDO2 security keys (such as YubiKey) and Windows Hello for Business are engineered to resist device code and AiTM mfa phishing attacks. Standard SMS codes and authenticator app tokens are not.
- Enable Safe Links and Safe Attachments in Microsoft Defender for Office 365. These features add a layer of URL scanning and attachment analysis that can intercept phishing lures before employees see them.
- Train employees to recognize device code lures. Any email directing a recipient to enter a code at an external website — even a legitimate-looking Microsoft URL — should be treated as suspicious unless the employee initiated the authentication request.
- Monitor inbox rules actively. Post-compromise, attackers commonly create forwarding or filtering rules in Outlook to redirect emails. Unexpected new rules are a reliable indicator of a successful account compromise.
- Audit OAuth application permissions in your Microsoft 365 admin center. Unfamiliar authorized applications may indicate token theft has already occurred.
- Restrict device code flow via Conditional Access policies if your organization does not use it for legitimate purposes. Blocking this authentication method entirely eliminates this specific attack vector.
The Bigger Picture: PhaaS and the Economics of Cheap Attacks
Kali365 is not an isolated product. It is a symptom of a maturing criminal marketplace where sophisticated attack capabilities are packaged as monthly subscriptions. QR code phishing — another MFA-adjacent technique — doubled in Q1 2026 according to Microsoft’s threat data. Adversary-in-the-middle toolkits have proliferated across Telegram, dark web forums, and private criminal channels.
The economics are stark. $250 buys access to infrastructure that, if it succeeds once against an account with access to financial systems or customer records, delivers a return many multiples of that cost. This is no longer the domain of nation-state attackers targeting enterprise networks. It is a commodity capability available to low-skill opportunists targeting any business that stores credentials online.
The FBI’s warning signals that the threat landscape for small businesses has materially shifted. Attackers are no longer relying on poorly formatted scam emails. They are deploying polished, low-cost, high-yield tools that specifically target the authentication systems businesses were told to trust.
What to Do If You Think Your Business Was Already Hit
If you suspect your organization has already been targeted by an mfa phishing attack using device code techniques, the response window is narrow. OAuth tokens typically remain valid for hours to days after they are issued. Acting quickly limits the blast radius.
Start with your Microsoft 365 admin center. Navigate to Azure Active Directory and review the list of OAuth consent grants. Any application authorized in the past 72 hours that your IT team did not deliberately configure should be treated as a potential indicator of compromise. Revoke the token immediately and document the application ID for follow-up.
Next, check Outlook inbox rules across affected accounts. Attackers who successfully complete an mfa phishing attack commonly set forwarding rules to an external address to maintain information access even after the token expires or is revoked. Microsoft Purview’s audit log can surface rule creation events with timestamps.
Notify your cyber insurance carrier if you carry a policy that covers breach events. Many small business policies now require notification within 24-72 hours of discovering a potential compromise to preserve coverage eligibility. A confirmed incident that led to data access could qualify as a reportable incident depending on the data involved and the jurisdictions in which you operate.
Finally, use the incident as a forcing function to accelerate the phishing-resistant MFA rollout. Every day a business operates on legacy authenticator apps after becoming aware of Kali365 is a day of known, avoidable exposure.
Frequently Asked Questions About MFA Phishing Attacks
Does enabling MFA protect my business from Kali365?
Only partially. Authenticator apps and SMS codes guard against password theft but are bypassed by device code techniques. Phishing-resistant authentication — FIDO2 security keys and Windows Hello for Business — are the only methods proven effective against this class of threat. Every mfa phishing attack that uses device codes specifically targets the gap between “has MFA” and “has the right MFA.”
How do I know if my Microsoft 365 account has been compromised?
Check for unexpected inbox rules in Outlook, unfamiliar authorized applications in your Microsoft 365 admin center, and sign-in activity from unfamiliar locations or devices. Microsoft’s Defender portal provides alerts for anomalous OAuth token grants.
Who is targeted by Kali365?
The platform targets Microsoft 365 business accounts broadly. Healthcare, financial services, professional services, and technology firms have been most frequently targeted, but small businesses in every sector face exposure whenever they use Microsoft 365 for email and collaboration.
Can my current email security vendor stop this attack?
URL filtering and email gateway solutions can block known malicious domains but may not catch device code mfa phishing attack lures that route victims to genuine Microsoft URLs. Phishing-resistant MFA is the most reliable technical control.
What should I do right now?
Audit which MFA methods are enabled across your Microsoft 365 tenant. If you are using only SMS or app-based OTP, schedule an upgrade to phishing-resistant MFA. Use the AI-powered automation tools in your business stack to set up proactive security monitoring workflows. For teams consolidating their business operations, the ASM platform is designed to reduce the number of disparate systems — and the number of credential surfaces — your business exposes to threats like Kali365.