< Back to all clusters
[TECHNOLOGY] · Germany, India · 8 sources

FBI warns of Kali365 phishing-as-a-Service targeting Microsoft 365

The U.S. Federal Bureau of Investigation has issued an alert about Kali365, a phishing‑as‑a‑Service platform that hijacks OAuth access and refresh tokens to gain persistent access to Microsoft 365 accounts, bypassing multi‑factor authentication. The FBI recommends blocking the device‑code flow in conditional‑access policies.

Cisco Talos reported that phishing was the initial access vector in more than half of its Q2 2026 incident engagements, a rise from one‑third in Q1. The report highlighted new delivery methods such as QR‑code PDFs and the use of device‑code phishing and AI‑driven attacks. An ARToken platform was identified, exposing over 80 API endpoints for token theft and related operations.

In Germany, phishing accounted for over 50 % of all security incidents in the second quarter of 2026, with additional threats including pre‑installed smartphone malware and vishing attacks. The same period saw a surge in ransomware activity, with attacks comprising just over one‑fifth of engagements.

Research presented at Black Hat Europe emphasized that ransomware groups, such as LockBit, treat reputation as a critical asset, influencing media coverage and victim response strategies. The overall landscape underscores persistent security gaps—from outdated access controls to weak passwords and insufficient employee training—that continue to be exploited by cyber‑criminals.

Entities: CISOs · Cisco Talos · Cofense · Employees · Federal Bureau of Investigation · IBM Security · Kali365 · LockBit · Microsoft · Verizon

Claims

What the coverage asserts, and how well corroborated each claim is across sources.

  • [○ 1 SOURCE] In Germany, phishing accounted for more than 50 % of all security incidents in Q2 2026. (German security report)
  • [○ 1 SOURCE] Phishing was the initial access vector in over 50 % of Cisco Talos incident engagements in Q2 2026, up from one‑third in Q1. (Cisco Talos research)
  • [○ 1 SOURCE] Ransomware attacks made up just over one‑fifth of the engagements examined by Cisco Talos in Q2 2026. (Cisco Talos research)
  • [○ 1 SOURCE] LockBit ransomware‑as‑a‑service group had 194 affiliates between 2022‑2024, with 80 affiliates receiving payment after successful attacks. (Black Hat Europe presentation)
  • [○ 1 SOURCE] The ARToken phishing‑as‑a‑Service platform exposed more than 80 API endpoints for device‑code phishing and related attacks. (Cisco Talos investigation)
  • [○ 1 SOURCE] The FBI warned that the Kali365 platform hijacks OAuth access and refresh tokens to gain persistent access to Microsoft 365 accounts, bypassing MFA. (FBI warning article)
  • [○ 1 SOURCE] Campaign‑based phishing detection is recommended over IOC‑centric approaches to address modern, polymorphic phishing attacks. (Cofense analysis)
  • [○ 1 SOURCE] Common security gaps include outdated access‑control systems, blind‑spot camera placement, weak passwords, lack of equipment maintenance, and limited employee training. (Security best‑practice article)