Source-linked briefing Technology

FBI Warns of New PhaaS Campaign Targeting Microsoft 365 OAuth Tokens

FBI Warns of New PhaaS Campaign Targeting Microsoft 365 OAuth Tokens

The FBI has flagged a phishing-as-a-service operation, dubbed Kali365, that uses AI-generated emails and legitimate-looking Microsoft verification pages to steal OAuth tokens. With token access, attackers can pivot into Outlook, Teams, and OneDrive without traditional login hurdles, enabling persistent access to corporate environments.

Original headline

The FBI warns Microsoft 365 services are being bombarded with new phishing emails — here are 3 steps you can take to stay safe