FBI warns about Kali365 and Microsoft 365 token hijacking

On 21 May 2026 the FBI issued a public service announcement about Kali365, a newly identified phishing-as-a-service platform circulating on Telegram. The platform facilitates the hijacking of Microsoft 365 access tokens.

The FBI strongly recommends that organisations restrict or fully block device code authentication flows using conditional access policies, and block authentication transfer from computers to mobile devices.

What this means for your business

Attacks that hijack the access token itself get past multi-factor authentication, because the user has already completed sign-in. For organisations that have placed email, files and collaboration in Microsoft 365, a successful attack grants access to nearly everything without looking abnormal. The device code flow is a rarely used but still open gap in many tenants.

Berigo recommends

  • Block the device code authentication flow in conditional access, and permit it only for the few scenarios that genuinely need it.
  • Block authentication transfer from computers to mobile devices.
  • Set up alerting on Microsoft 365 sign-ins from unexpected device types or locations.
  • Walk the management team and key users through what a token hijacking attempt looks like in practice.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch