You Did Everything Right. Real Page, Valid Certificate, MFA Approved — and They're In.
In a public service announcement, the FBI warned businesses about Kali365 — a "phishing-as-a-service" kit rented over Telegram for as little as $250 a month. It steals Microsoft 365 access without ever touching your password, and it walks straight past multi-factor authentication. You don't need to be a hacker to use it. You just need a subscription. Here's how it works, and the one setting that shuts it down.
For years, the reassuring story about cybercriminals was that real attacks required real skill. Building convincing phishing infrastructure, evading detection, bypassing multi-factor authentication — that took expertise most criminals didn't have. The barrier to entry was your friend.
That barrier just collapsed. On May 21, 2026, the FBI issued a public service announcement (PSA I-052126) warning businesses about a new tool called Kali365 — and the warning is worth every small business owner's attention, because it represents a fundamental shift in who can attack you and how easily.
Kali365 is "phishing-as-a-service." It's a crime kit sold by subscription, rented over the messaging app Telegram for as little as $250 for 30 days. You don't build anything. You don't need technical skill. You subscribe, point it at a list of targets, and the software does the work — including the part that used to be hardest: getting past multi-factor authentication.
the monthly subscription price to rent a tool that breaks into Microsoft 365 accounts and bypasses MFA
For roughly the cost of a business software subscription, someone with almost no hacking ability can now run attacks that used to require an expert. The subscription includes AI-generated phishing emails free of the typos that used to give scams away, ready-made templates impersonating trusted services, a live dashboard tracking which targets have taken the bait, and the infrastructure to steal Microsoft 365 access tokens. It industrializes what used to be artisanal.
Here's the part that should make every business owner sit up: Kali365 works even when your multi-factor authentication is fully deployed and working exactly as designed. It doesn't defeat MFA by cracking it. It sidesteps it entirely — by stealing the token that proves you already passed the MFA check. And it does this without ever capturing your password.
How the attack actually works — and why it's so hard to spot
The genius and the danger of Kali365 is that it abuses a legitimate Microsoft feature. There's no fake website. No misspelled domain. No spoofed login page. The victim authenticates on the real microsoft.com, using their real password and their real authenticator app. Here's the sequence:
Why this matters more for small businesses
The campaigns using this technique have targeted manufacturing, education, insurance, financial services, healthcare, and government — a spread that tells you attackers aren't being selective. When the tool is this cheap and this automated, there's no reason to target only large organizations. The economics of "phishing-as-a-service" reward volume, and small businesses running Microsoft 365 are the largest pool of targets in the world.
Small businesses are also less likely to have configured the specific setting that stops this attack — because until the FBI's warning, few had reason to know it existed. That's the good news hiding in this story: the single most effective defense is a configuration change most businesses can make inside settings they already pay for.
The four defenses — starting with the one that shuts it down
Block device code flow — the single setting that closes the door
The #1 FBI fix · FreeThe FBI's top recommendation is direct: block the device code authentication flow. This is the specific mechanism Kali365 abuses, and most businesses have no legitimate need for it. Blocking it closes the exact door this attack walks through — without affecting normal sign-ins.
Upgrade to phishing-resistant MFA
Configuration · Low costPush notifications, text codes, and authenticator codes can all be relayed to an attacker in a token-theft attack. Phishing-resistant MFA — passkeys or FIDO2 hardware security keys — ties authentication to a physical device, making the token far harder to hijack. It's the durable answer as these attacks evolve.
Be able to revoke a stolen session in minutes
Process · FreeBecause this attack grants a standing token, the critical question after a suspected compromise is how fast you can invalidate it. A password reset alone doesn't kill a stolen token — you have to revoke the sessions. Knowing how to do this before you need to is the difference between a contained incident and a widening one.
Teach the team the one rule that beats this specific lure
Training · FreeTraditional phishing training — check the domain, look for typos — doesn't help here, because the domain is real. The rule that does help is specific: never enter a device code you didn't personally initiate. If an email asks you to go enter a code somewhere, that's the red flag, even if the page it sends you to is genuinely Microsoft's.
The bigger shift this represents
Kali365 is one product, and by the time you read this the FBI's warning may have driven it underground or a competitor may have replaced it — other kits using the same technique already exist. But the trend it represents is permanent: the most capable attack techniques are being packaged, automated, and sold as subscriptions to people who couldn't have built them. The skill barrier that used to protect small businesses is gone.
The response isn't panic — it's the same discipline this whole series has argued for. The attack is sophisticated; the defense is a configuration change and a clear rule. Block the device code flow. Upgrade your MFA. Know how to revoke a session. Tell your team the one rule. Four steps, most of them free, against a threat that costs your attacker $250 a month. That asymmetry — cheap attack, cheaper defense — is still, even now, on your side. But only if you use it.
📚 Credential Security Series — Read the full series
Find out if the defenses that stop this are actually in place. Veriti Spottr's beta is free.
Get your CyberScore →
Comments
Post a Comment