FBI warns of hacking campaign stealing Microsoft 365 accounts without passwords

Cybercriminals are exploiting a new 'Phishing-as-a-Service' tool, Kali365, to bypass Microsoft 365 security, including multi-factor authentication. This sophisticated scam tricks users into authorizing access via a legitimate Microsoft login page, granting hackers persistent entry to emails and files without passwords. Security experts warn this trend is a direct response to improved corporate defenses.

FBI warns of hacking campaign stealing Microsoft 365 accounts without passwords
Cybercriminals are exploiting a new 'Phishing-as-a-Service' tool, Kali365, to bypass Microsoft 365 security, including multi-factor authentication. This sophisticated scam tricks users into authorizing access via a legitimate Microsoft login page, granting hackers persistent entry to emails and files without passwords. Security experts warn this trend is a direct response to improved corporate defenses.