CIO Brief: Phishing Kits Are Now a Subscription Business
The short version: In May 2026, the FBI warned about Kali365, a subscription service sold on Telegram that lets criminals take over Microsoft 365 accounts even when they're protected by multi-factor authentication. Bypassing MFA is now a product anyone can buy.
What changed
Defeating MFA used to require skill and custom tools. Now criminals rent ready-made kits with instructions and support. Several such services appeared in 2026 alone.
The business impact
- More attacks, because the barrier to entry is low.
- Email takeover leading to payment fraud and data theft.
- False confidence in standard MFA.
What still works
- Phishing-resistant sign-in (passkeys, security keys) that can't be relayed by fake pages.
- Requiring company-managed devices for access to email and files, so stolen sessions don't work elsewhere.
- Blocking unnecessary sign-in methods, such as device code sign-in.
- Fast detection and revocation of suspicious sessions.
Questions to ask your team
- Can someone access our company email from any computer if they steal a user's session?
- Which employees have phishing-resistant sign-in today?
- Do we block sign-in methods most users never need?
What good looks like
Phishing-resistant MFA for high-risk roles now and everyone over time, managed-device requirements for sensitive data, unnecessary sign-in methods blocked, and session monitoring.
The decision
Treat "we have MFA" as the starting point, not the finish line. Fund the move to phishing-resistant sign-in and device-based access this year.
Sources
- Kali365 and the FBI Warning (May 2026): MFA-Bypass Phishing Kits Go Mainstream Incident Teardowns
- How to Use Token Protection and Compliant-Device Policies Against Token Theft How-To & Hardening
- Detecting MFA Bypass Phishing Kit: Defender XDR and Sentinel Hunting Queries Detection & Response