The New Microsoft 365 Scam That Does Not Need Your Password

Most people know the usual phishing warning signs: bad grammar, strange links, suspicious attachments, or a fake login page asking for your password.

But a new scam targeting Microsoft 365 users is changing the rules.

The FBI is warning about a phishing-as-a-service platform called Kali365, and what makes it especially concerning is that attackers do not always need your password to get in. In some cases, they can gain access even when multifactor authentication is turned on.

That should get every business owner’s attention.

How This Scam Works

Kali365 targets Microsoft 365 accounts, including Outlook, Teams and OneDrive. Instead of asking victims to type in their password on a fake website, attackers abuse a legitimate Microsoft device-code login process.

You have probably seen this kind of login before. It is similar to when a smart TV or streaming app gives you a short code and asks you to enter it on another device to sign in.

The process itself is real. The scam happens when a cybercriminal starts the login from their own device and tricks the victim into approving it.

A user may receive what looks like a normal email about a shared document, voicemail, invoice, cloud file or account verification. The message provides a code and tells them to enter it on a Microsoft verification page. Because the page can be legitimate, the request may feel safe.

But once the user enters that code, they may unknowingly approve the attacker’s device.

From there, the attacker can capture access tokens that act like digital keys to the account. That can give them access to Microsoft 365 services without needing the user’s actual password.

Why This Is So Dangerous

Many businesses feel safer once multifactor authentication is turned on. And to be clear, MFA is still important. It blocks many attacks.

But this scam is a reminder that MFA is not a magic shield.

The danger here is that the victim is not simply handing over a password. They are being tricked into approving access through a legitimate sign-in process. That makes the attack harder to recognize in the moment.

Once a cybercriminal gets into a business account, the damage can spread quickly. They may be able to read emails, access shared files, review Teams messages, study invoice patterns, impersonate employees, and send convincing messages from a real company account.

That is where this becomes more than an IT issue, it becomes a business risk.

One compromised inbox can lead to fake wire requests, stolen client information, vendor fraud, ransomware attempts or internal confusion that slows down the entire team.

Small Businesses Are Not Too Small to Be Targeted

A common misconception is that cybercriminals only care about large corporations. In reality, small and midsized businesses can be attractive targets because they often rely heavily on Microsoft 365 but may not have the same monitoring, policies or security controls as larger organizations.

Attackers know this.

They also know that employees are busy. A quick email that says “review this document,” “your voicemail is ready,” or “verify your account” can blend into a normal workday. All it takes is one person trying to move fast.

That is why awareness matters. This scam is not just about technology. It is about behavior, training and knowing when to pause.

Red Flags to Watch For

Be cautious if you receive an unexpected message asking you to enter a Microsoft device code.

Watch out for messages involving:

The simplest rule is this: if you did not start the sign-in, do not enter the code.

How to Protect Your Business

Start by educating your team. Employees should know that not every real-looking Microsoft page means the request is safe. If a code appears in an unexpected email, Teams message or text, they should stop and verify through a trusted channel.

Businesses should also review Microsoft 365 security settings, monitor suspicious sign-ins, check connected devices, review active sessions and make sure old or unnecessary access is removed.

For stronger protection, organizations should work with their IT provider to evaluate policies around device-code authentication, conditional access, token activity, account alerts and user training.

Cybercriminals are getting better at making scams look normal. Your defense has to get better at spotting what does not belong.

Final Takeaway

The Kali365 warning is a clear reminder that cybersecurity is no longer just about protecting passwords.

Today’s attackers are looking for ways around the tools businesses trust most. They are using legitimate login pages, real authentication flows and convincing messages to make employees feel comfortable doing something risky.

The best protection is a layered approach: strong security settings, continuous monitoring, employee education and a team that knows when to slow down before clicking, approving or entering a code.

Because sometimes, the most dangerous scam is the one that does not look fake at all.

Got Questions or Topics You’d Like Covered ? Connect with us here!

Let’s innovate, optimize, and secure your business—together!

In the meantime, Stay Secure!!

Written by:  Kaitlyn Darling Marketing Associate at Teknovate Consulting Partners.