FBI warns of major phishing scam
Digest more
The FBI warns of Kali365, a phishing scam exploiting Microsoft 365 verification tools to bypass security, granting hackers ongoing access to accounts. Users are urged to review authentication practices.
The FBI warned on May 21 that cybercriminals are increasingly targeting Microsoft 365 users with sophisticated phishing scams. The scam uses a tool called “Kali365” to steal account access tokens and bypass multi-factor authentication protections.
Scammers have found a way to weaponize an official Microsoft email address in order to spread their cyber crimes. Credit: Samuel Boivin/NurPhoto via If you've ever received an email from "[email protected],
The loophole allows spammers and scammers to send emails from a legitimate Microsoft email address typically used for sending genuine account alerts.
Scammers are reportedly abusing an internal Microsoft email account to send phishing-style spam links disguised as official alerts.
Scam emails are getting better at looking official. This one claims to be an urgent warning from Microsoft about your email account. It looks serious. It feels time sensitive. And that is exactly the point. Lily reached out after something about the ...