My whole job practically lives inside Microsoft 365. I'm in Outlook all day long, bouncing between Teams chats with my coworkers, and pulling files out of SharePoint more times than I can count. So when I saw the FBI had issued a warning about a new way to break into Microsoft 365 accounts, it stopped me cold. If you use Microsoft 365 for your job, your business, or even just personal email and files, this is worth laying your eyes on.

What The Kali365 Microsoft 365 Scam Actually Is

The FBI's Internet Crime Complaint Center issued a public service announcement about a phishing kit called Kali365, first spotted in April 2026 and sold through Telegram as a subscription service. According to the FBI's IC3 announcement, Kali365 lets cybercriminals capture Microsoft 365 access tokens and bypass multi-factor authentication without ever stealing your password. The subscription model means someone with very little technical skill can rent the toolkit and start targeting victims almost immediately, using AI-generated phishing emails and ready-made campaign templates.

How This Microsoft 365 Phishing Scam Actually Works

What makes this one sneaky is that it does not rely on a fake login page. The FBI describes it in four steps. First, an attacker sends a phishing email pretending to be from a trusted service, something like a shared document or a verification request, that includes a short device code. Second, you go to Microsoft's own real device login page and enter that code, thinking you are verifying yourself. Third, the moment you enter it, you have actually authorized the attacker's device to access your account instead. Fourth, the attacker now holds what is called an OAuth token, a kind of digital key that keeps them logged into your account without needing your password or another MFA prompt.

Why Changing Your Password Might Not Be Enough

Because the attacker never touches your password in the first place, the usual advice to change it after a suspected breach does not fully solve the problem here. The FBI notes that once someone holds a stolen OAuth token, they can keep quiet, persistent access to your Outlook email, Teams chats, and OneDrive or SharePoint files, often watching for wire transfer requests or invoice details, until that token is specifically revoked.

How To Protect Your Microsoft 365 Account From This Scam

For business owners and IT administrators, the FBI recommends creating a conditional access policy that blocks or restricts device code flow for general users, while first auditing current usage so you don't accidentally lock out a legitimate business process. The FBI also suggests blocking authentication transfer policies, which stop someone from moving a login session from a computer to a mobile device, and keeping emergency access accounts excluded from restrictions to avoid locking yourself out. The FBI's announcement also points businesses toward the Cybersecurity and Infrastructure Security Agency's phishing guidance document, which lays out broader best practices for stopping phishing attacks before they start.

For everyday users, the advice is simpler. If you get an email asking you to enter a short code on a Microsoft page, and you are not actively setting up a new device at that exact moment, treat it as an attack and do not enter the code.

What To Do If You Think You Were Targeted

If you suspect your Microsoft 365 account has already been compromised, the FBI recommends logging out of every active session tied to your account and filing a report at IC3.gov, including any phishing emails, suspicious login times or locations, and any unfamiliar devices or sessions you find attached to your account. I know I will be keeping a much closer eye on any device code prompts that show up in my own inbox from now on.

6 Of The Most Common Scams Affecting Montanans

Thanks to the Montana Department of Revenue we know these 6 scams are what Montana residents will have to deal with most commonly. Knowing these scams will help protect you and your identity.

Gallery Credit: Nick Northern

Don't Answer Calls from These 10 Area Codes - It's a Scam

Those who are in the know about telephone and identity theft scams say these area codes produce the most problem calls for their clients. Unless you personally know someone who might be calling from one of the following area codes, you might want to let that phone call go unanswered.

Gallery Credit: Bruce Mikells