{"id":15001,"date":"2026-06-15T08:44:28","date_gmt":"2026-06-15T08:44:28","guid":{"rendered":"https:\/\/wildgreenquest.com\/?p=15001"},"modified":"2026-06-15T08:44:28","modified_gmt":"2026-06-15T08:44:28","slug":"the-fbi-just-issued-an-urgent-warning-for-anyone-using-microsoft-teams-outlook-or-onedrive-over-a-new-phishing-scheme","status":"publish","type":"post","link":"https:\/\/wildgreenquest.com\/?p=15001","title":{"rendered":"The FBI just issued an urgent warning for anyone using Microsoft Teams, Outlook, or OneDrive over a new phishing scheme"},"content":{"rendered":"<p><br \/>\n<br \/><\/p>\n<p class=\"wp-block-paragraph\">The security measure millions rely on to protect their accounts may not be as foolproof as they think.<br \/><a rel=\"nofollow\" href=\"https:\/\/www.ic3.gov\/PSA\/2026\/PSA260521?utm_source=syndication&amp;pubDate=20260525\" target=\"_blank\" rel=\"noreferrer noopener\">The Federal Bureau of Investigation<\/a>\u00a0is warning the public about a fast-spreading\u00a0<a rel=\"nofollow\" href=\"https:\/\/www.inc.com\/amaya-nichole\/2025-americans-lost-billions-to-scams-on-social-media-group-most-susceptible\/91343952\" target=\"_blank\" rel=\"noreferrer noopener\">scam<\/a>\u00a0targeting users of popular\u00a0<a rel=\"nofollow\" href=\"https:\/\/www.inc.com\/amrita-khalid\/microsoft-office-price-increase-alternative-software.html\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft<\/a>\u00a0365 products, including Outlook, Teams, and OneDrive. The scheme allows cybercriminals to capture Microsoft authentication tokens, bypassing multifactor authentication without needing a user\u2019s password.<\/p>\n<p class=\"wp-block-paragraph\">At the center of the scheme is a hacking platform called Kali365. Unlike traditional\u00a0<a rel=\"nofollow\" href=\"https:\/\/www.inc.com\/chloe-aiello\/the-fbi-just-busted-a-global-phishing-empire-targeting-microsoft-365-accounts-heres-how-they-beat-mfa\/91330893\" target=\"_blank\" rel=\"noreferrer noopener\">phishing<\/a>\u00a0attacks that rely on stealing credentials, Kali365 targets OAuth device codes\u2014digital keys that allow applications to access data without requiring a password\u2014giving cybercriminals access to Microsoft 365 accounts and a wide range of sensitive information.<\/p>\n<p class=\"wp-block-paragraph\">The subscription-based service, which was first spotted in April 2026, has been promoted largely through Telegram and,\u00a0<a rel=\"nofollow\" href=\"https:\/\/www.bitdefender.com\/en-us\/blog\/hotforsecurity\/fbi-kali365-phishing-kit-breaks-microsoft-365-accounts-no-password-required\" target=\"_blank\" rel=\"noreferrer noopener\">according to Bitdefender<\/a>, is available to scammers for as little as $250 per month or $2,000 a year.<\/p>\n<p class=\"wp-block-paragraph\">What makes the threat particularly alarming is that it can gain access to a user\u2019s account without a password. \u201cKali365 lowers the barrier of entry, providing less-technical attackers access to\u00a0<a rel=\"nofollow\" href=\"https:\/\/www.inc.com\/artificial-intelligence\" target=\"_blank\" rel=\"noreferrer noopener\">AI<\/a>-generated phishing lures, automated campaign templates, real-time targeted individual\/entity tracking dashboards, and OAuth token capture capabilities,\u201d the FBI said.<\/p>\n<p class=\"wp-block-paragraph\">With security researchers reporting\u00a0<a rel=\"nofollow\" href=\"https:\/\/arcticwolf.com\/resources\/blog\/token-bingo-dont-let-your-code-be-the-winner\/\" target=\"_blank\" rel=\"noreferrer noopener\">hundreds of Kali365 attacks<\/a>\u00a0in April alone, the threat is already materializing.\u00a0<\/p>\n<h2 id=\"h-how-the-scheme-unfolds\" class=\"wp-block-heading\">How the scheme unfolds<\/h2>\n<p class=\"wp-block-paragraph\">The attack follows a deceptively simple sequence. A victim receives a phishing email designed to look like it came from a trusted cloud service. The email contains a device code and instructs the recipient to visit a legitimate Microsoft verification page to enter it.&nbsp;<\/p>\n<p class=\"wp-block-paragraph\">The moment the user does this, the user has unknowingly handed the attacker full access to their account.<\/p>\n<p class=\"wp-block-paragraph\">Once the code is entered, the attacker captures the OAuth access token, granting them full entry into the victim\u2019s Microsoft 365 account. From there, they can freely navigate Outlook, Teams, and OneDrive without ever needing a password or completing any additional authentication steps.<\/p>\n<p class=\"wp-block-paragraph\">What makes the scam particularly convincing is that there is no fake website to spot and no misspelled domain name, making it difficult for a user to distinguish the phishing attempt from a legitimate request.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThis phishing scam is getting more sophisticated by the day, with AI-generated lures and automated templates,\u201d\u00a0<a rel=\"nofollow\" href=\"https:\/\/www.facebook.com\/FBI\/posts\/today-the-fbi-released-a-psa-warning-the-public-about-kali365an-emerging-phishin\/1401980001975562\/\" target=\"_blank\" rel=\"noreferrer noopener\">one user wrote in response to the FBI\u2019s warning<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">However, the FBI says there are steps users can take to protect themselves, including not opening any links with access codes that you didn\u2019t request. Additionally, those who have been affected by the Kali365 phishing kit can file a complaint with the\u00a0<a rel=\"nofollow\" href=\"https:\/\/www.ic3.gov\/\" target=\"_blank\" rel=\"noreferrer noopener\">Internet Crime Complaint Center.<\/a><\/p>\n<p class=\"wp-block-paragraph\"><em>\u2014Amaya Nichole, News Writer<\/em><\/p>\n<p class=\"wp-block-paragraph\"><em>This article\u00a0<a rel=\"nofollow\" href=\"https:\/\/www.inc.com\/amaya-nichole\/fbi-just-issued-urgent-warning-anyone-using-microsoft-over-new-phishing-scheme\/91351360\" target=\"_blank\" rel=\"noreferrer noopener\">originally appeared<\/a>\u00a0on\u00a0<\/em>Fast Company<em>\u2019s sister website, Inc.com.<\/em>\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Inc.&nbsp;<em>is the voice of the American entrepreneur. We inspire, inform, and document the most fascinating people in business: the risk-takers, the innovators, and the ultra-driven go-getters that represent the most dynamic force in the American economy.<\/em><\/p>\n<p><br \/>\n<br \/><a href=\"https:\/\/www.fastcompany.com\/91552566\/fbi-warning-microsoft-teams-outlook-onedrive-phishing-scheme-kali365\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The security measure millions rely on to protect their accounts may not be as foolproof as they think.The Federal Bureau of Investigation\u00a0is warning the public about a fast-spreading\u00a0scam\u00a0targeting users of popular\u00a0Microsoft\u00a0365 products, including Outlook, Teams, and OneDrive. The scheme allows cybercriminals to capture Microsoft authentication tokens, bypassing multifactor authentication without needing a user\u2019s password. At<\/p>\n","protected":false},"author":1,"featured_media":15002,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[37],"tags":[],"class_list":["post-15001","post","type-post","status-publish","format-standard","has-post-thumbnail","category-brand-spotlights"],"_links":{"self":[{"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=\/wp\/v2\/posts\/15001","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=15001"}],"version-history":[{"count":0,"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=\/wp\/v2\/posts\/15001\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=\/wp\/v2\/media\/15002"}],"wp:attachment":[{"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=15001"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=15001"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wildgreenquest.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=15001"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}