Close Menu
    Facebook X (Twitter) Instagram
    TRENDING :
    • For U.S. Soccer’s CEO, the World Cup stakes are bigger than a trophy
    • US and Iran Exchange Fire, Pentagon Raises an Israeli Spy Threat, a Jihadist-Rebel Alliance Pressures Mali 
    • The FBI just issued an urgent warning for anyone using Microsoft Teams, Outlook, or OneDrive over a new phishing scheme
    • 7 Fastest Growing Food Franchises to Watch
    • Why talented women keep getting passed over for promotions—and 3 strategies to help
    • Russia’s New Warning Shot From Space
    • Why I designed Charlotte Tilbury Beauty as a technology company
    • Pokémon Go Data Used For Drone Warfare
    Populist Bulletin
    • Home
    • US Politics
    • World Politics
    • Economy
    • Business
    • Headline News
    Populist Bulletin
    Home»Business»The FBI just issued an urgent warning for anyone using Microsoft Teams, Outlook, or OneDrive over a new phishing scheme
    Business 3 Mins Read

    The FBI just issued an urgent warning for anyone using Microsoft Teams, Outlook, or OneDrive over a new phishing scheme

    Business 3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
    Follow Us
    Google News Flipboard
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The security measure millions rely on to protect their accounts may not be as foolproof as they think.
    The Federal Bureau of Investigation is warning the public about a fast-spreading scam targeting users of popular Microsoft 365 products, including Outlook, Teams, and OneDrive. The scheme allows cybercriminals to capture Microsoft authentication tokens, bypassing multifactor authentication without needing a user’s password.

    At the center of the scheme is a hacking platform called Kali365. Unlike traditional phishing attacks that rely on stealing credentials, Kali365 targets OAuth device codes—digital keys that allow applications to access data without requiring a password—giving cybercriminals access to Microsoft 365 accounts and a wide range of sensitive information.

    The subscription-based service, which was first spotted in April 2026, has been promoted largely through Telegram and, according to Bitdefender, is available to scammers for as little as $250 per month or $2,000 a year.

    What makes the threat particularly alarming is that it can gain access to a user’s account without a password. “Kali365 lowers the barrier of entry, providing less-technical attackers access to AI-generated phishing lures, automated campaign templates, real-time targeted individual/entity tracking dashboards, and OAuth token capture capabilities,” the FBI said.

    With security researchers reporting hundreds of Kali365 attacks in April alone, the threat is already materializing. 

    How the scheme unfolds

    The attack follows a deceptively simple sequence. A victim receives a phishing email designed to look like it came from a trusted cloud service. The email contains a device code and instructs the recipient to visit a legitimate Microsoft verification page to enter it. 

    The moment the user does this, the user has unknowingly handed the attacker full access to their account.

    Once the code is entered, the attacker captures the OAuth access token, granting them full entry into the victim’s Microsoft 365 account. From there, they can freely navigate Outlook, Teams, and OneDrive without ever needing a password or completing any additional authentication steps.

    What makes the scam particularly convincing is that there is no fake website to spot and no misspelled domain name, making it difficult for a user to distinguish the phishing attempt from a legitimate request.

    “This phishing scam is getting more sophisticated by the day, with AI-generated lures and automated templates,” one user wrote in response to the FBI’s warning.

    However, the FBI says there are steps users can take to protect themselves, including not opening any links with access codes that you didn’t request. Additionally, those who have been affected by the Kali365 phishing kit can file a complaint with the Internet Crime Complaint Center.

    —Amaya Nichole, News Writer

    This article originally appeared on Fast Company’s sister website, Inc.com. 

    Inc. is the voice of the American entrepreneur. We inspire, inform, and document the most fascinating people in business: the risk-takers, the innovators, and the ultra-driven go-getters that represent the most dynamic force in the American economy.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    For U.S. Soccer’s CEO, the World Cup stakes are bigger than a trophy

    June 15, 2026

    7 Fastest Growing Food Franchises to Watch

    June 15, 2026

    Why talented women keep getting passed over for promotions—and 3 strategies to help

    June 15, 2026
    Top News
    Business 3 Mins Read

    The AWS outage reveals the web’s massive centralization problem

    Business 3 Mins Read

    U.K. banks and government tech systems going down. University students in Australia struggling to complete…

    Is having AI ghostwrite your Valentine’s Day messages a good idea?

    February 8, 2026

    Using AI Gave Me Free Time — So I Turned It Into My Competitive Edge

    September 22, 2025

    The Aging Population is Driving Demand for Quality In-Home Care Services

    September 15, 2025
    Top Trending
    Business 8 Mins Read

    For U.S. Soccer’s CEO, the World Cup stakes are bigger than a trophy

    Business 8 Mins Read

    The World Cup arriving on American soil is more than a cultural…

    US Politics 2 Mins Read

    US and Iran Exchange Fire, Pentagon Raises an Israeli Spy Threat, a Jihadist-Rebel Alliance Pressures Mali 

    US Politics 2 Mins Read

    With the midterm elections now firmly upon us, the question is whether…

    Business 3 Mins Read

    The FBI just issued an urgent warning for anyone using Microsoft Teams, Outlook, or OneDrive over a new phishing scheme

    Business 3 Mins Read

    The security measure millions rely on to protect their accounts may not…

    Categories
    • Business
    • Economy
    • Headline News
    • Top News
    • US Politics
    • World Politics
    About us

    The Populist Bulletin was founded with a fervent commitment to inform, inspire, empower and spark meaningful conversations about the economy, business, politics, government accountability, globalization, and the preservation of American cultural heritage.

    We are devoted to delivering straightforward, unfiltered, compelling, relatable stories that resonate with the majority of the American public, while boldly challenging false mainstream narratives that seem to only serve entrenched elitists, and foreign interests.

    Top Picks

    For U.S. Soccer’s CEO, the World Cup stakes are bigger than a trophy

    June 15, 2026

    US and Iran Exchange Fire, Pentagon Raises an Israeli Spy Threat, a Jihadist-Rebel Alliance Pressures Mali 

    June 15, 2026

    The FBI just issued an urgent warning for anyone using Microsoft Teams, Outlook, or OneDrive over a new phishing scheme

    June 15, 2026
    Categories
    • Business
    • Economy
    • Headline News
    • Top News
    • US Politics
    • World Politics
    Copyright © 2025 Populist Bulletin. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.