FBI warns Microsoft users about passwordless scam
The article warns Microsoft 365 users about a phishing-as-a-service platform called Kali365 that can bypass traditional password-based defenses by abusing Microsoft’s device-code login flow. Attackers send convincing phishing emails that trick users into entering a legitimate Microsoft verification code, thereby authorizing the attacker’s device and exposing OAuth access and refresh tokens. Once compromised, attackers may access Outlook, Teams, and OneDrive without needing the password or triggering additional MFA prompts. The piece emphasizes that the threat is especially dangerous for small businesses because a stolen account can be used to impersonate employees, redirect invoices, and spread further fraud. It advises users and IT teams to avoid entering unsolicited codes, review account activity, revoke suspicious sessions, and, where appropriate, restrict device-code flow through conditional access policies.