Times of India | FBI warns of hacking campaign stealing Microsoft 365 accounts without passwords

AI generated summary, Read the full article for complete information.

The FBI issued a public warning about a new Phishing‑as‑a‑Service toolkit called Kali365 that enables hackers to hijack Microsoft 365 accounts—including Outlook, Teams and OneDrive—without ever needing a password, by exploiting Microsoft’s “device code flow” to bypass multi‑factor authentication. Victims receive a convincing phishing email that directs them to a legitimate Microsoft verification page, where they enter a short security code; because this occurs on an authentic site and passes MFA, Microsoft issues an OAuth access token that the attacker captures, granting them a persistent backdoor to the account. Distributed mainly via Telegram, Kali365 lowers the technical barrier for criminals by providing AI‑generated phishing lures, automated campaign templates, and real‑time tracking dashboards. To mitigate the threat, the FBI advises organizations to restrict or block device code flow through conditional‑access policies, audit existing usage, limit authentication transfers, and report any incidents to the Internet Crime Complaint Center (IC3).

Read more: https://timesofindia.indiatimes.com/technology/tech-news/fbi-warns-of-hacking-campaign-stealing-microsoft-365-accounts-without-passwords/articleshow/131446721.cms

#FBI #Microsoft #Kali365 #IC3 #MFA

FBI warns of hacking campaign stealing Microsoft 365 accounts without passwords

The Federal Bureau of Investigation (FBI) recently issued a public warning about a dangerous new hacking platform that allows cybercriminals to hijack Microsoft 365 accounts, including Outlook email, Teams, and OneDrive cloud storage, without ever needing a password. The announcement posted by the agency raised alarm over a “Phishing-as-a-Service” toolkit called Kali365, explaining that the platform is specifically designed to bypass multi-factor authentication (MFA) – the standard security feature that text-messages or apps a code to prove a user's identity.

The Times of India

FBI Warns of $388 Million Lost to Crypto ATM Scams

The FBI's Internet Crime Complaint Center received over 13,400 complaints about crypto ATM scams in 2025, with victims losing a staggering $388 million - a 58% jump in losses from the previous year. This alarming trend is part of a broader surge in cybercrime, with over 1 million complaints filed and nearly $21 billion in losses reported last year.

https://osintsights.com/fbi-warns-of-388-million-lost-to-crypto-atm-scams?utm_source=mastodon&utm_medium=social

#CryptoAtmScams #EmergingThreats #FinancialCrimes #Fbi #Ic3

FBI Warns of $388 Million Lost to Crypto ATM Scams

Learn how crypto ATM scams cost $388 million in 2025 and how to protect yourself from these growing threats - read the FBI's warning now.

OSINTSights
💔 Romance Scams Hitting Alaskans
Who’s scamming? And how much are victims losing? Federal prosecutors say these online romance schemes are spreading fast and the damage goes beyond money. 💸
Find out what officials are warning.
👉🏿 https://tinyurl.com/ycx8emh8
#RomanceScams #FraudAlert #Alaska #ConsumerWarning #OnlineSafety #IC3 #Love
The train out there just broke down.
And so will mine a few min after this pic.
Coincidence or do we blame the - hold on to your hats! - 2 cm of snow?
#Chur, #Graubünden #Switzerland
#SBB #TrainTravel #ICN #IC3 #snow
@[email protected]

It looks like a scam that should be investigated.

Appears the profile was deleted.

#FBI #IC3


#train We're on a Danish DSB #IC3 train to Germany. Probably for the last, or at least one of the last, times.

While I'm sure the newer trains will be adequate. I'll also certainly miss the feeling of luxury of the current ones. With the quiet running, and spacious and warm interior the IC3 trains are just a pleasure to travel on.

🚨 Watch out for fake IC3 websites as FBI warns of scammers are cloning its #IC3.gov to steal your personal and financial info.

Read: https://hackread.com/fbi-warning-fake-ic3-websites-steal-data/

#CyberSafety #FBI #Scam #Fraud #CyberCrime

FBI Warns of Fake IC3 Websites Designed to Steal Personal Data

Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread

Hackread - Latest Cybersecurity, Hacking News, Tech, AI & Crypto
#FBI "released its Internet Crime Report 2024, highlighting US$16.6 billion in losses reported to the Internet Crime Complaint Center ( #IC3) over the past year." industrialcyber.co/reports/fbis... #cybersec #ransomware #phishing #tech #data #cybercrime #natsec #CISA #NIST #security

FBI’s Internet Crime Report 20...
Bluesky

Bluesky Social