FBI warns of major phishing scam
Digest more
Scammers are impersonating Microsoft with urgent deadline threats and fake legal language to rush victims into clicking dangerous links.
The FBI warned on May 21 that cybercriminals are increasingly targeting Microsoft 365 users with sophisticated phishing scams. The scam uses a tool called “Kali365” to steal account access tokens and bypass multi-factor authentication protections.
The loophole allows spammers and scammers to send emails from a legitimate Microsoft email address typically used for sending genuine account alerts.
The FBI warns of Kali365, a phishing scam exploiting Microsoft 365 verification tools to bypass security, granting hackers ongoing access to accounts. Users are urged to review authentication practices.
Scammers are reportedly abusing an internal Microsoft email account to send phishing-style spam links disguised as official alerts.