Microsoft 365CIO BriefingsNews

CIO Brief: Phishing Kits Are Now a Subscription Business

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

The short version: In May 2026, the FBI warned about Kali365, a subscription service sold on Telegram that lets criminals take over Microsoft 365 accounts even when they're protected by multi-factor authentication. Bypassing MFA is now a product anyone can buy.

What changed

Defeating MFA used to require skill and custom tools. Now criminals rent ready-made kits with instructions and support. Several such services appeared in 2026 alone.

The business impact

  • More attacks, because the barrier to entry is low.
  • Email takeover leading to payment fraud and data theft.
  • False confidence in standard MFA.

What still works

  • Phishing-resistant sign-in (passkeys, security keys) that can't be relayed by fake pages.
  • Requiring company-managed devices for access to email and files, so stolen sessions don't work elsewhere.
  • Blocking unnecessary sign-in methods, such as device code sign-in.
  • Fast detection and revocation of suspicious sessions.

Questions to ask your team

  • Can someone access our company email from any computer if they steal a user's session?
  • Which employees have phishing-resistant sign-in today?
  • Do we block sign-in methods most users never need?

What good looks like

Phishing-resistant MFA for high-risk roles now and everyone over time, managed-device requirements for sensitive data, unnecessary sign-in methods blocked, and session monitoring.

The decision

Treat "we have MFA" as the starting point, not the finish line. Fund the move to phishing-resistant sign-in and device-based access this year.

Sources

  1. Source
kali365 phishing impactKali365 PhaaS2026

More on this story