Attack + Goal
April 2026 on Microsoft 365 enterprise users. Goal was broad corporate account takeovers and extortion.
Result
Widespread corporate account compromises, multi-factor authentication bypasses, and unauthorized access to cloud communications and files.
Method
Device code phishing via the Kali365 kit, hijacking OAuth tokens to bypass passwords and multi-factor checks.
Financial Impact
Unquantified direct theft losses, forensic investigations, and account remediation expenses.
In April 2026, cybercriminals launched Kali365, a phishing platform distributed via Telegram that targets corporate Microsoft 365 environments. The blast radius spans organizations worldwide, allowing low-skilled threat actors to gain full access to victim Outlook emails, Teams messaging, and OneDrive file storage. The attack relies entirely on credential and token theft using a device code authorization trick. Attackers send lures posing as document-sharing alerts, prompting employees to enter codes into legitimate login portals. Once completed, the platform steals valid OAuth access tokens. This grants the attackers persistent session access while completely bypassing multi-factor authentication without requiring passwords. The resulting intrusions expose organizations to corporate espionage, data theft, and internal business email compromise.
PreBreach ID Guard flags stolen OAuth tokens, and auto-remediates by cutting off persistent Microsoft 365 access even when MFA has already been bypassed.