The Headline
FBI warns about Kali365 phishing kit
Key Facts
- FBI issues a warning on May 21 about a new AI-powered attack using the Kali365 phishing kit that enables threat actors to obtain Microsoft 365 access tokens and bypass multi-factor authentication protocols without intercepting user credentials.

- Kali365 is a phishing-as-a-service platform that was first discovered in April 2026 and is distributed through Telegram channels to assist cybercriminals in compromising Microsoft 365 accounts.1
- The service allows attackers to capture OAuth tokens, granting them access to various Microsoft 365 services such as Outlook, Teams, and OneDrive without requiring a password or additional MFA challenges.

- Kali365 significantly lowers the barrier of entry for less-technical attackers by providing access to AI-generated phishing lures, automated campaign templates, and token capture capabilities.

