FBI sounds alarm on phishing tool that steals Microsoft 365 accounts without passwords
What to know about Cybersecurity Threat
FBI sounds alarm on phishing tool that steals Microsoft 365 accounts without passwords See more of our coverage in your search results.
Coverage spectrum
Coverage gap: Low Left coverage7 sources compared across this story cluster. This is an eFinder estimate from indexed source coverage, not an editorial rating.
What happened
FBI sounds alarm on phishing tool that steals Microsoft 365 accounts without passwords See more of our coverage in your search results.
Why it matters
Add The New York Post on GoogleThe FBI is warning that a new hacking platform is allowing cybercriminals to hijack Microsoft 365 accounts — including Outlook, Teams and OneDrive — while bypassing multi-factor authentication entirely.
Common ground
The bureau posted a public service announcement last week sounding the alarm about the “Phishing-as-a-Service” toolkit known as Kali365, which is being used to steal Microsoft 365 access tokens and gain entry to victim accounts without intercepting passwords.
Perspective signals
The tension in the story is sharpened by Loaded Language, Appeal to Fear: language that can make the dispute feel more urgent, personal, or adversarial than the underlying facts alone.
Follow-up questions
- What new context would change how readers understand this Cybersecurity Threat story?
- What evidence would most clearly confirm or weaken the claim that sophisticated attack tools are sold to low-skilled criminals via subscription services on Telegram and dark web forums?
- How does this story connect Cybersecurity Threat with FBI Public Safety Warning over the next few days?
psychologyPropaganda Techniques Detected
eFinder identified 2 propaganda techniques in this article. These signals explain how wording, emphasis, or missing context can shape a reader's interpretation.
fact_checkClaims Checked
eFinder analyzed this article and checked 12 claims against available evidence, cross-references, web search, and Wikipedia. Here is what the fact-checking layer found.
https://www.ic3.gov/PSA/2026/PSA260521
https://www.aol.com/articles/fbi-warns-phishing-scam-targeti…
https://www.probablypwned.com/article/fbi-kali365-phaas-micr…
https://en.wikipedia.org/wiki/2020_United_States_federal_gov…
https://en.wikipedia.org/wiki/Microsoft
https://en.wikipedia.org/wiki/Microsoft_365
https://www.ic3.gov/PSA/2026/PSA260521
https://cybersecuritynews.com/kali365-phaas-microsoft-365/
https://www.bleepingcomputer.com/news/security/fbi-warns-of-…
https://spycloud.com/blog/device-code-phishing-the-new-aitm-…
https://dirkjanm.io/phishing-for-microsoft-entra-primary-ref…
https://www.linkedin.com/posts/rkvincent_kali365-phishing-as…
https://www.hornetsecurity.com/en/blog/kali365-device-code-p…
https://www.linkedin.com/posts/hkcert_fbi-warns-of-kali365-p…
https://medium.com/@anyrun/kali365-phaas-overview-9906627c5e…
https://news.google.com/stories/CAAqNggKIjBDQklTSGpvSmMzUnZj…
https://www.bleepingcomputer.com/news/security/fbi-warns-of-…
https://www.hornetsecurity.com/en/blog/kali365-device-code-p…
https://www.obsidiansecurity.com/blog/what-is-token-theft-oa…
https://appomni.com/learn/saas-security-fundamentals/oauth-t…
https://medium.com/@maxwellcross/breaking-sso-oauth-token-th…
https://www.linkedin.com/posts/twin-cities-technology-profes…
https://www.bitdefender.com/en-us/blog/hotforsecurity/fbi-ka…
https://timesofindia.indiatimes.com/technology/tech-news/fbi…