"They Don't Need Your Password Anymore" — What the Kali365 Threat Means for Your Business
The FBI just issued a warning about Kali365 — a phishing kit that doesn't steal your password. It steals something worse: a token that gives attackers ongoing access to your Microsoft 365 environment. Here's what every small business owner needs to know.
Last week, the FBI dropped a warning that should make every small business owner sit up straight. It's called Kali365 — a phishing kit being sold on Telegram that doesn't bother stealing your password.
It steals something better: a token that says "this device is authorized."
Here's how simple the attack is: Someone sends you an email that looks like it's from Microsoft. "You've been shared a document." "Your IT team needs you to verify your device." The usual tricks. The email has a code and a link to a real Microsoft page — not a fake one. You enter the code. Nothing suspicious happens.
But in those three seconds, you just handed an attacker the keys to your entire Microsoft 365 environment. Email. Teams. OneDrive. Everything.
No password stolen. No MFA prompt you ignored. You followed the instructions, and you still lost.
How the Token Trick Actually Works
Microsoft 365 uses something called "device code flow." It's designed for devices that can't open a browser — smart TVs, IoT hardware, that kind of thing. You enter a short code on a real Microsoft page, and the device is authenticated.
Kali365 exploits this legitimate feature. The attacker generates a device code, sends it to you, and waits. The moment you enter it, Microsoft issues an OAuth token to the attacker's device — and that token doesn't expire just because you change your password.
The attacker now has persistent, undetected access. They can read your email, download files from OneDrive, search through Teams conversations, forward messages — all without triggering a single MFA challenge.
Why Small Businesses Are the Target
This isn't a Fortune 500 problem. It's a small business problem.
Large enterprises have security teams, conditional access policies, and 24/7 monitoring. They blocked device code flow years ago. Most SMBs haven't touched those settings since the day their Microsoft tenant was created.
The attackers know this. Kali365 is being sold as a service — people with zero technical skills can buy a subscription, pick a template, and launch a campaign in minutes. The barrier to entry is gone.
If you're running a 10-person insurance agency, a 5-person real estate firm, or a solo law practice, you're not just a target. You're the preferred target.
The Real Risk Isn't Just Data Theft
Most people think about phishing in terms of stolen data. But with token-based access, the threat is deeper:
- The attacker can sit silently in your inbox for weeks — reading every client communication, every contract, every negotiation
- They can use your compromised account to phish your clients, your partners, and your vendors — from an email address everyone already trusts
- They can set up forwarding rules that send copies of every email to an external address, and you'd never notice unless you went looking
This is the kind of breach that doesn't announce itself. You find out when a client asks why you sent them a strange invoice — or worse, when you don't find out at all.
Three Steps to Lock This Down Today
I'm not going to give you a 20-step security checklist you'll never complete. Here are three things that actually matter:
1. Block device code flow in Azure AD. This is the single most impactful move you can make. Create a conditional access policy that blocks device code authentication for all users. Ten minutes of work eliminates this entire attack vector.
2. Audit your sign-in logs. Go to your Microsoft 365 admin center, pull up sign-in logs, and look for "deviceCode" in the authentication details. If you see entries you don't recognize, investigate immediately.
3. Check your forwarding rules. Open Exchange admin center and review mailbox forwarding rules. Look for anything sending email outside your domain. Attackers love setting these up quietly.
If any of this sounds like Greek to you, that's not a character flaw — it's why businesses need a technology partner who handles this stuff proactively.
This Is What "Managed IT" Actually Means
Here's the thing about cybersecurity in 2026: the threats evolve faster than most business owners can track. You're running a company. You don't have time to monitor FBI alerts, audit Azure policies, and review sign-in logs.
That's the entire point of having a managed technology partner.
At Marcoby, we don't wait for our clients to ask about the latest threat. We read the PSA the day it drops, we check every managed tenant, and we either confirm you're protected or we fix it before you even knew there was a problem.
That's the difference between reactive IT support and proactive technology management. One waits for you to call. The other calls you first.
The Landscape Is Always Moving. You Need a Guide.
The Kali365 threat is just the latest example of a pattern that's only accelerating: the tools businesses rely on are under constant, evolving attack — and the security defaults that came with your account aren't enough anymore.
You can't out-read the threat landscape. You can't out-patch the attackers. But you can out-partner them.
When you have a team watching the horizon, vetting the alerts, and implementing the fixes — the specific threat matters less. Your posture is already strong.
That's the business we're building at Marcoby. Not just fixing things when they break, but architecting systems that stay ahead of the curve. Whether it's securing your Microsoft 365 environment, consolidating your fragmented tech stack, or building the workflows that make your operations hum — we show up as a partner, not a vendor.
Technology shouldn't be something you survive. It should be something that helps you thrive.
At Marcoby, You're Technically Family.
🔍 Run a free Business IT Health Check → 📅 Book a consultation →