Skip to content

Leadership1 publisher2 min readPublished

Blocking Kali365 means deciding which business processes still need device code flow

The FBI says a subscription kit sold on Telegram harvests Microsoft 365 OAuth tokens through device code lures. The mitigation it recommends is a tenant-wide block, and somebody has to decide the exceptions.

The Board Room · Leadership desk

What happened

  • The FBI has issued a public service announcement about Kali365, a phishing-as-a-service platform first seen in April 2026 that lets subscribers take Microsoft 365 access tokens.
  • The lure is an email impersonating cloud productivity and document-sharing services, carrying a device code and instructions to enter it on a legitimate Microsoft verification page.
  • The subscription bundles AI-generated phishing lures, automated campaign templates, real-time target tracking dashboards and OAuth token capture, which the FBI says lowers the barrier of entry.
  • The bureau's first recommended protection is a conditional access policy blocking device code flow for all users, with limited exceptions for required business processes.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • decision The exception list moves a risk decision above the security team: whoever approves it is choosing which processes keep an authentication path the FBI has now flagged.
  • constraint Awareness programmes built on spotting a fraudulent domain have nothing to flag here, because the code is entered on Microsoft's own verification page.
  • exposure The remediation itself creates a failure mode: a block written without carve-outs can lock out the emergency access accounts kept for when other authentication fails.
  • capability Token capture and campaign dashboards are now available to buyers who could not build them, so the number of campaigns depends on how many people subscribe.

Writing the exception list is a management decision. Somebody has to say which business processes are allowed to keep using an authentication flow the bureau has just described as the way in, and the FBI tells defenders to look before they write: audit existing device code flow usage to identify legitimate dependencies first [12].

Order of operations matters because the control can fail in two directions. Block too broadly, too early, and you take out whatever legitimate process depended on the flow. The FBI puts the same caution in as a carve-out: if you cannot completely restrict device code flow usage, exclude emergency access accounts to prevent lockouts [14]. It also recommends blocking authentication transfer policies, which stop users moving an authentication session from a computer to a mobile device [13].

In the sequence the FBI describes, the target's own action is the correct one: go to the real Microsoft verification page and enter the device code, unknowingly authorizing the attacker's device [7]. None of the four protections in the announcement asks anything of that person [17]. Each is a change to tenant configuration, and for user-facing advice the PSA points to CISA's Phishing Guidance: Stopping the Attack Cycle at Phase One [16].

The bureau's framing is that Kali365 obtains Microsoft 365 access tokens and bypasses MFA without intercepting the user's credentials [3], and that once access and refresh tokens are captured [8], the attacker keeps reaching Outlook, Teams and OneDrive without a password or any additional MFA challenge [9]. The second factor is not broken in that account of it. The user completes it, and the tokens that result go to a device the user never saw. "Restricting device code flow to limit or block device authentication codes can help prevent or limit this style of attack," the FBI wrote [10].

Kali365 is distributed primarily through Telegram [2], and it is the subscription that supplies persistent access to a target's Microsoft 365 environment [4]. The announcement does not include a victim count or name the sectors targeted [18]. It asks anyone affected to file with IC3 and to include phishing email headers and bodies, suspicious logins with time, IP address and location, and any unauthorized devices or active sessions added to the account [15].

What to watch

  • Any IC3 follow-up that quantifies Kali365 losses or names the sectors being targeted.
  • Whether Microsoft changes the device code flow default so tenants do not have to block it themselves.
  • Whether other kits sold on Telegram add the same token capture against non-Microsoft identity providers.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories