FBI Alert: Computer Login Trick Exposed

A $250 crime kit called Kali365 now lets low-skill crooks break into Microsoft 365 accounts without your password or your multi-factor code.

Story Snapshot

  • FBI says Kali365 lets attackers hijack Outlook, Teams, and OneDrive by abusing Microsoft’s own login flow
  • The kit grabs hidden access tokens, so crooks skip passwords and multi‑factor authentication entirely
  • Phishing-as-a-service means almost anyone can rent these tools and launch “professional” attacks
  • Simple account settings and common-sense habits can shut most of this down before it starts

The FBI’s warning: a new scam that breaks the old rules

The Federal Bureau of Investigation did not fire off this alert over a simple fake-email scam. Agents warned that an emerging “phishing-as-a-service” platform called Kali365 is being rented on criminal channels and used to break into Microsoft 365 accounts that people think are well protected.

The target is not your password. The target is a special kind of secret key called an OAuth token, which Microsoft uses to keep you logged in across Outlook, Teams, and OneDrive.

Once attackers steal that token, they do not need your password or your multi-factor code to keep accessing your email, files, and chats.[3] That is what makes this worth an FBI public service announcement, not just a quiet tech bulletin.

It undercuts the “I turned on multi-factor, I’m safe” story that security trainers have sold for years. The tactic is not science fiction. It uses the same Microsoft sign-in pages you see every day.[3]

How Kali365 turns a simple email into full account takeover

Kali365 leans on a feature known as the device code flow. Microsoft built this flow so people can sign in to devices like smart TVs that cannot show a full login box.

Attacks start with a phishing email that appears to be from a trusted cloud or document service, containing a “secure” code and step-by-step instructions.

The email tells you to go to a real Microsoft verification page and type in that code, which feels safe because the site and padlock look perfect.[1]

Behind the scenes, that code links to the attacker’s own rogue application, not to a document you asked for. When you complete the steps, you are actually authorizing that criminal app to connect to your Microsoft 365 account.

Microsoft then hands out OAuth access and refresh tokens tied to your account, and Kali365 quietly captures them. From that moment on, the attacker can open your Outlook, read your Teams chats, and pull files from OneDrive as if they were you, without any further login prompts.[3]

Why this matters more than the usual phishing scare

Most adults have learned to spot the classic scam: bad spelling, weird links, and fake login pages. Kali365 is dangerous because it keeps most of the tricks inside real Microsoft infrastructure.

Victims land on official Microsoft login pages and see a normal padlock icon, so the usual “check the URL” advice is not enough. On top of that, the kit is sold as a subscription service that wraps complex attacks in point-and-click tools for unskilled criminals.

The FBI advisory says Kali365 offers artificial-intelligence-generated phishing lures, automated templates, live dashboards to track who clicked, and built-in token capture. That should ring a bell for anyone who cares about basic fairness and security.

Big tech chose convenience and “seamless login” over clear, simple prompts people can understand. Now criminals rent that complexity by the month and target small businesses, churches, local governments, and families who rely on Microsoft 365 for daily life.[3]

What this says about Big Tech, government, and common sense defense

There is a pattern here that should bother anyone who values personal responsibility and limited but focused government. Private platforms like Microsoft 365 centralize vast amounts of data within a single identity system. When that identity is abused, everything falls at once.

The FBI is now stuck warning the public after the fact, while Microsoft rushes out best-practice tips to clean up its own risky design choices.[3] That is not a healthy long-term model for national resilience.

The lesson is simple: do not trust any “smart” system to think for you. Disable features you do not use, especially device-code sign-in, which your organization can restrict, as multiple security write-ups recommend.[2]

Treat every “enter this code” email as hostile unless you requested it. Watch for new devices or unusual sessions in your account settings, and report them fast through Microsoft’s tools and the Internet Crime Complaint Center if something looks off.

Sources:

[1] Web – FBI issues urgent Kali365 security warning for Teams, Outlook, …

[2] Web – FBI warns of Kali365 phishing scam targeting Microsoft 365 users

[3] Web – FBI warns about PhaaS platform used to access Microsoft 365 …