The risk is no longer just MFA bypass. Kali365 turns Microsoft’s device-code flow into a reusable token-grab, so a phished login can leave an attacker inside Microsoft 365 even after a password reset.
The FBI now describes Kali365 as a Telegram-distributed phishing-as-a-service platform first seen in April 2026. Reported activity has climbed into the hundreds, and the toolkit targets Microsoft 365 access and refresh tokens across Outlook, Teams, and OneDrive.
That shifts the problem from credential theft to persistent OAuth access. Authorized app grants and stolen tokens can keep working without new MFA prompts, which extends compromise into data theft, fraud, extortion, and ransomware staging.