Multi-factor authentication has made it much harder for attackers to take over corporate accounts. But phishing attacks are evolving, and attackers are finding ways to bypass the protection MFA provides.
A recent FBI warning about Kali365, a phishing-as-a-service platform targeting Microsoft 365 users, highlights this shift.
Attackers Don’t Always Need Your Password
Traditional phishing attacks try to steal usernames, passwords, and MFA codes.
Kali365 takes a different approach.
The attacker sends a phishing message that directs the victim to Microsoft’s legitimate device login page. The victim enters a code provided by the attacker and unknowingly authorizes the attacker’s device.
The result? The attacker can obtain valid OAuth tokens that provide access to Microsoft 365 resources.
No fake Microsoft login page is necessarily required. No password has to be stolen.
And the victim may even complete MFA as part of the process.
Why This Matters
This attack demonstrates an important change in the phishing landscape.
MFA protects authentication. It does not protect users from being tricked into authorizing the wrong device or application.
That means organizations need to look beyond passwords and MFA when building their phishing defenses.
The initial attack can still begin with something very familiar: a phishing message and a link.
The difference is what happens after the user clicks.
Instead of sending the victim to a fake login page, attackers can abuse legitimate authentication services and cloud infrastructure to make the attack look much more convincing.
Phishing Is Becoming More Sophisticated
Kali365 is part of a broader trend in which Phishing-as-a-Service makes sophisticated attacks available to more threat actors.
The technical attack may involve OAuth, access tokens and cloud identity systems, but the human element remains critical.
The attacker still needs the user to trust the message and follow its instructions.
This is why organizations should continue to focus on detecting phishing links and suspicious messages before users reach the authentication stage.
What Organizations Can Do
The FBI recommends organizations evaluate whether they need Microsoft’s Device Code Authentication flow and consider restricting it where appropriate.
Security teams should also monitor authentication activity for unusual IP addresses, locations, devices and session behavior, and ensure that incident response procedures address compromised tokens and sessions, not only stolen passwords.
Most importantly, organizations should remember that a legitimate website does not automatically mean a legitimate request.
The Bottom Line
Phishing is no longer just about stealing passwords.
Attackers are increasingly targeting authenticated access itself.
As organizations strengthen identity security with MFA and other controls, phishing protection remains a critical layer of defense.
Because sometimes the attacker doesn’t need to break through your security.
They just need to convince your employee to let them in.
