Cyber attackers are hijacking Microsoft Outlook, Teams and 365 log-ins, FBI says
The FBI has issued a warning about a new phishing tool called Kali365 that allows cyber attackers to access Microsoft 365 users' accounts without needing their password. The tool bypasses multi-factor authentication and can capture authorization tokens to grant access to Microsoft software, including Outlook and Teams. To protect themselves, users are advised to create a conditional access policy and learn to spot phishing attempts.
- ▪The Kali365 phishing platform was first seen in April and is primarily distributed through the messaging app Telegram.
- ▪The scam starts with a phishing email that contains a device code with instructions to visit a legitimate Microsoft verification page.
- ▪The FBI recommends creating a conditional access policy and checking who currently has access to code flow usage to prevent Kali365 attacks.
The Hill files mainly under politics. We currently carry 1,451 of its stories.
Story provenance
Source · retrieval · rights · ranking — open for full record
inspect →
Attribution is not the same as permission. This drawer separates discovery metadata, excerpts, WeSearch-generated summaries, reuse status, and whether the publisher receives the visit. Nothing here claims a legal grant the publisher has not made.
Record
| Original publisher | The Hill |
| Canonical URL | https://thehill.com/policy/technology/5897640-cyber-attackers-are-hijacking-microsoft-outlook-teams-and-365-log-ins-fbi-says/ |
| Publication time | Wed, 27 May 2026 21:34:16 +0000 |
| Retrieval time | 2026-05-27T22:13:05.882Z |
| Last seen | 2026-05-27T22:13:08.552Z |
| Headline source | Publisher (no WeSearch rewrite) |
| Excerpt source | publisher body |
| Excerpt method | First ~120 words (~800 chars) of extracted publisher body, fair-use limited. |
| Summary | WeSearch · cerebras-chat (WeSearch summarizer) |
| Summary source text | contentText |
| Citation coverage | Summary is a WeSearch-generated derivative; primary citation is the original publisher URL. |
| Cluster | hiFxzYJlLaSo |
| Cluster logic | Grouped by semantic title/content similarity across sources within a rolling window. Same-publisher template collisions are excluded from coverage comparison. |
| Ranking reason | Story pages are not engagement-ranked. Hub feeds use recency, with optional source-diversified chronological ordering (cap consecutive stories per source). No personalized ranking. |
| Publisher visit | Yes — open original |
| Substitutes article? | No — link-out required for full text |
Rights status (four layers)
WeSearch handling by dimension
| Indexing | May the item be indexed (stored, ranked, made findable)? | Allowed |
| Snippet | May a short excerpt of the publisher's text be shown? | Allowed |
| AI summary | May WeSearch generate its own short summary of the article? | Limited |
| Retrieval / RAG | May the content be exposed for third-party retrieval-augmented generation? | Not asserted |
| Model training | May the content be used to train AI models? | Not asserted |
| Commercial reuse | May the content be reused commercially? | Not permitted |
Basis: Derived from the published RSS/Atom feed. Contact: [email protected]. Reviewed: 2026-07-24.
Opening excerpt (first ~120 words) tap to expand
Technology Cyber attackers are hijacking Microsoft Outlook, Teams and 365 log-ins, FBI says Comments: by Alix Martichoux - 05/27/26 5:34 PM ET Comments: Link copied by Alix Martichoux - 05/27/26 5:34 PM ET Comments: Link copied NOW PLAYING (NEXSTAR) – A new phishing tool is allowing cyber attackers to get access to Microsoft 365 users’ accounts without even needing to know your password, the FBI said in a warning issued to the public on Thursday. The phishing platform, called Kali365, was first seen in April, according to the FBI. It’s primarily distributed through the messaging app Telegram and allows cyber attackers to bypass multi-factor authentication. The scam starts with a lure, typically a phishing email impersonating a trusted source like a document sharing service.
…
Excerpt limited to ~120 words for fair-use compliance. The full article is at The Hill.