Times of India | FBI warns of hacking campaign stealing Microsoft 365 accounts without passwords
AI generated summary, Read the full article for complete information.
The FBI issued a public warning about a new Phishing‑as‑a‑Service toolkit called Kali365 that enables hackers to hijack Microsoft 365 accounts—including Outlook, Teams and OneDrive—without ever needing a password, by exploiting Microsoft’s “device code flow” to bypass multi‑factor authentication. Victims receive a convincing phishing email that directs them to a legitimate Microsoft verification page, where they enter a short security code; because this occurs on an authentic site and passes MFA, Microsoft issues an OAuth access token that the attacker captures, granting them a persistent backdoor to the account. Distributed mainly via Telegram, Kali365 lowers the technical barrier for criminals by providing AI‑generated phishing lures, automated campaign templates, and real‑time tracking dashboards. To mitigate the threat, the FBI advises organizations to restrict or block device code flow through conditional‑access policies, audit existing usage, limit authentication transfers, and report any incidents to the Internet Crime Complaint Center (IC3).

FBI warns of hacking campaign stealing Microsoft 365 accounts without passwords
The Federal Bureau of Investigation (FBI) recently issued a public warning about a dangerous new hacking platform that allows cybercriminals to hijack Microsoft 365 accounts, including Outlook email, Teams, and OneDrive cloud storage, without ever needing a password. The announcement posted by the agency raised alarm over a “Phishing-as-a-Service” toolkit called Kali365, explaining that the platform is specifically designed to bypass multi-factor authentication (MFA) – the standard security feature that text-messages or apps a code to prove a user's identity.






