Kali365 Phishing Service Microsoft 365 Account Compromise | MSSP Advisory
HighCredible Report
DateMay 25, 2026
📋Executive Summary
The FBI has identified Kali365, a phishing-as-a-service platform that compromises Microsoft 365 accounts by exploiting OAuth device code authentication to steal session tokens and bypass MFA. Attackers use this platform to gain persistent access to M365 environments without triggering traditional authentication alerts. The service automates the entire attack chain from credential harvesting to token theft.
⚠️Why It Matters for MSSPs
Your RMM and PSA platforms likely authenticate through M365, making your entire client management stack vulnerable to session hijacking that bypasses your MFA protections. Every client running M365 becomes a retention risk because this attack method defeats the security controls you probably recommended and they paid for.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Phishing
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.