Close Menu
    Trending
    • Why UK’s Makerfield by-election matters far beyond one parliamentary seat | Politics News
    • George Pickens gives massive update on Cowboys future
    • Elon Musk’s Twitter deal looked like a $44 billion disaster. Now, his investors stand to make a 200% return—thanks to a brilliant (and controversial) M&A move
    • NASA data reveals weird x-ray changes in the exploded ruins of dead stars
    • Will Lebanon Become The Next Gaza?
    • DJ Fat Tony Defends Addressing Brooklyn Beckham’s Family Feud
    • Austria return from long World Cup absence with nervy 3-1 win over Jordan
    • England vs Croatia – World Cup 2026: Kane, predictions, TV channel, kickoff | World Cup 2026 News
    Benjamin Franklin Institute
    Wednesday, June 17
    • Home
    • Politics
    • Business
    • Science
    • Technology
    • Arts & Entertainment
    • International
    Benjamin Franklin Institute
    Home»Business»The FBI just issued an urgent warning for anyone using Microsoft Teams, Outlook, or OneDrive over a new phishing scheme
    Business

    The FBI just issued an urgent warning for anyone using Microsoft Teams, Outlook, or OneDrive over a new phishing scheme

    Team_Benjamin Franklin InstituteBy Team_Benjamin Franklin InstituteJune 15, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email VKontakte Telegram
    Share
    Facebook Twitter Pinterest Email Copy Link

    The security measure millions rely on to protect their accounts may not be as foolproof as they think.
    The Federal Bureau of Investigation is warning the public about a fast-spreading scam targeting users of popular Microsoft 365 products, including Outlook, Teams, and OneDrive. The scheme allows cybercriminals to capture Microsoft authentication tokens, bypassing multifactor authentication without needing a user’s password.

    At the center of the scheme is a hacking platform called Kali365. Unlike traditional phishing attacks that rely on stealing credentials, Kali365 targets OAuth device codes—digital keys that allow applications to access data without requiring a password—giving cybercriminals access to Microsoft 365 accounts and a wide range of sensitive information.

    The subscription-based service, which was first spotted in April 2026, has been promoted largely through Telegram and, according to Bitdefender, is available to scammers for as little as $250 per month or $2,000 a year.

    What makes the threat particularly alarming is that it can gain access to a user’s account without a password. “Kali365 lowers the barrier of entry, providing less-technical attackers access to AI-generated phishing lures, automated campaign templates, real-time targeted individual/entity tracking dashboards, and OAuth token capture capabilities,” the FBI said.

    With security researchers reporting hundreds of Kali365 attacks in April alone, the threat is already materializing. 

    How the scheme unfolds

    The attack follows a deceptively simple sequence. A victim receives a phishing email designed to look like it came from a trusted cloud service. The email contains a device code and instructs the recipient to visit a legitimate Microsoft verification page to enter it. 

    The moment the user does this, the user has unknowingly handed the attacker full access to their account.

    Once the code is entered, the attacker captures the OAuth access token, granting them full entry into the victim’s Microsoft 365 account. From there, they can freely navigate Outlook, Teams, and OneDrive without ever needing a password or completing any additional authentication steps.

    What makes the scam particularly convincing is that there is no fake website to spot and no misspelled domain name, making it difficult for a user to distinguish the phishing attempt from a legitimate request.

    “This phishing scam is getting more sophisticated by the day, with AI-generated lures and automated templates,” one user wrote in response to the FBI’s warning.

    However, the FBI says there are steps users can take to protect themselves, including not opening any links with access codes that you didn’t request. Additionally, those who have been affected by the Kali365 phishing kit can file a complaint with the Internet Crime Complaint Center.

    —Amaya Nichole, News Writer

    This article originally appeared on Fast Company’s sister website, Inc.com. 

    Inc. is the voice of the American entrepreneur. We inspire, inform, and document the most fascinating people in business: the risk-takers, the innovators, and the ultra-driven go-getters that represent the most dynamic force in the American economy.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Telegram Copy Link

    Related Posts

    Business

    Elon Musk’s Twitter deal looked like a $44 billion disaster. Now, his investors stand to make a 200% return—thanks to a brilliant (and controversial) M&A move

    June 17, 2026
    Business

    Why employers should treat domestic violence as a workplace issue

    June 17, 2026
    Business

    Work-life balance doesn’t exist for working parents

    June 17, 2026
    Business

    Jeff Bezos says AI will cause ‘labor scarcity,’ not job loss

    June 16, 2026
    Business

    Robinhood lays off 10% of staff to flatten its organizational structure

    June 16, 2026
    Business

    6 things consumers should know about prices on goods now that the Iran war may be ending

    June 16, 2026
    Editors Picks

    Market Talk – April 30, 2026

    April 30, 2026

    Mets’ losing streak could mark end to playoff hopes

    April 19, 2026

    Why cloning anyone – even Jim Carrey – isn’t the best plan ever

    April 17, 2026

    What Astrology Says About Kim Kardashian & Lewis Hamilton

    February 14, 2026

    Chip export controls not major topic in China talks: US trade chief

    May 15, 2026
    About Us
    About Us

    Welcome to Benjamin Franklin Institute, your premier destination for insightful, engaging, and diverse Political News and Opinions.

    The Benjamin Franklin Institute supports free speech, the U.S. Constitution and political candidates and organizations that promote and protect both of these important features of the American Experiment.

    We are passionate about delivering high-quality, accurate, and engaging content that resonates with our readers. Sign up for our text alerts and email newsletter to stay informed.

    Latest Posts

    Why UK’s Makerfield by-election matters far beyond one parliamentary seat | Politics News

    June 17, 2026

    George Pickens gives massive update on Cowboys future

    June 17, 2026

    Elon Musk’s Twitter deal looked like a $44 billion disaster. Now, his investors stand to make a 200% return—thanks to a brilliant (and controversial) M&A move

    June 17, 2026

    Subscribe for Updates

    Stay informed by signing up for our free news alerts.

    Paid for by the Benjamin Franklin Institute. Not authorized by any candidate or candidate’s committee.
    • Privacy Policy
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.