Kali365 and the FBI Warning (May 2026): MFA-Bypass Phishing Kits Go Mainstream
In May 2026, the FBI warned about Kali365, a phishing-as-a-service platform first observed in April 2026 that lets cybercriminals obtain Microsoft 365...
Service
An independent, evidence-based view of your Microsoft 365 risk in two to three weeks.
Most Microsoft 365 tenants grew fast and were never reviewed end to end. Legacy sign-in methods, permanent global admins, permissive app consent and weak email protections are common — and they are exactly what phishing kits and business email compromise crews look for.
50–2,000 seat organizations on Microsoft 365 without a dedicated Microsoft security engineer.
Read-only roles such as Global Reader and Security Reader. Some free assessment tools need a one-time admin consent, which your administrator grants.
The assessment is diagnostic. Most clients continue with our Entra ID Hardening Sprint or a monthly retainer to implement the roadmap.
Secure Score is a useful input. We validate it, add checks it doesn't cover, and turn the results into a prioritized plan tied to business risk.
In May 2026, the FBI warned about Kali365, a phishing-as-a-service platform first observed in April 2026 that lets cybercriminals obtain Microsoft 365...
MFA-bypass phishing kits steal tokens rather than passwords. Two Entra ID controls make stolen tokens much less useful: token protection and...
Since February 2026, a phishing-as-a-service platform known as EvilTokens has been used to compromise Microsoft 365 accounts through OAuth device code...