Published on 8 August 2026
More than 80 US companies per week, and the wave of attacks has long been rolling through Europe too: A new criminal service platform called Kali365 makes it alarmingly easy for attackers to gain access to Microsoft 365 accounts – in a way that means even an activated two-factor authentication no longer offers reliable protection. For small and medium-sized businesses that manage their emails, documents and cloud data in Microsoft 365, this is one of the most serious threats of the year. We explain what lies behind the attack, why it is so dangerous – and what you should do now.
The renowned IT security portal The Hacker News reported on 5 August 2026 about a phishing-as-a-service platform called Kali365. The term phishing-as-a-service (PhaaS for short) describes a business model in which criminals rent out ready-made phishing tools as a paid service to other attackers – much like legitimate providers sell software on a subscription basis. So the buyer doesn't need to be a technical expert; they simply pay for a ready-to-use attack package.
What is special and dangerous about Kali365: The platform specifically targets Microsoft 365 and, in doing so, abuses legitimate login mechanisms provided by Microsoft itself. According to the report, more than 80 US companies are attacked each week. The method is explicitly also active in Europe – so German companies are by no means off the hook. And perhaps the most important point: the attack bypasses multi-factor authentication, that is, the additional security step (for example a code confirmation via an app) that is actually considered particularly secure.
To understand why Kali365 is so effective, you need to know about a mechanism that Microsoft actually built in as a convenience feature: the so-called device code flow.
This login method was originally intended for devices that don't allow convenient keyboard input – such as smart TVs or certain games consoles. Here, the device displays a short code that the user then enters on a second device (such as a smartphone) on an official Microsoft page. After confirmation, the first device is logged in. The clever twist for criminals: with this procedure, the user themselves authorises the login on a genuine Microsoft page.
This is exactly where Kali365 comes in. According to the report, the platform uses attacker-controlled device codes. Put simply: the attacker generates such a login code and gets their victim to enter and confirm this code on the genuine Microsoft login page. To the victim, everything looks legitimate – after all, it is the official Microsoft page. But by confirming it, the victim is in fact authorising the attacker's device.
Because the actual login takes place on the genuine Microsoft infrastructure and the user actively approves it, multi-factor authentication does not step in to provide protection: the second factor is handled as part of this process confirmed by the victim. The result is persistent, i.e. permanent, access to the account. The attacker thereby gains access to:
The term "persistent" is particularly alarming here: once obtained, access often remains in place even if the victim changes their password – because the authorisation granted is not the same as the password. Such access must therefore be revoked deliberately.
In principle, this threat affects all users of Microsoft 365. Since the attackers are not exploiting a security vulnerability in a particular software version, but abusing a legitimate login mechanism, there is no "safe version" that you could simply update to. In this case there is also no CVE number – that is, no official identifier for a classic software vulnerability – because it is not a programming error but the abuse of an intended function.
For small and medium-sized businesses in Germany, the situation is therefore clear: if you use Microsoft 365 for emails, documents or team collaboration, you belong to the potential target group. While the report primarily cites US companies with more than 80 attacks a week, it explicitly emphasises that the method is also active in Europe.
Since the underlying research material does not contain any specific check instructions from the vendor, we provide general guidance here, oriented towards the attack method described. The following in particular is suspicious:
Note: These points are general guidance. For a reliable assessment, you should, if in doubt, consult your IT service provider or a security expert.
Since there is no patch in the classic sense, protection lies above all in organisational and configuration measures as well as in raising your employees' awareness. The following steps are oriented towards the attack pattern described:
The severity of this threat is to be classified as high – and for good reason. A successful attack gives criminals access to the heart of digital business operations: emails, documents and cloud data. This opens the door to follow-on damage such as fraud via hijacked email accounts (for example fake invoices or payment instructions to business partners), industrial espionage, or the preparation of further attacks.
For companies in Germany, there is an additional legal dimension. As soon as an attacker gains access to emails and files, personal data is very likely to be affected too – such as customer data, contact information or HR data. Such unauthorised access can constitute a reportable data breach under the General Data Protection Regulation (GDPR). The GDPR stipulates that a breach of the protection of personal data must, as a rule, be reported to the competent supervisory authority within 72 hours of becoming known. In some circumstances, the affected individuals must also be informed.
For managing directors and decision-makers, this means: a security incident is not just an IT problem, but also a legal obligation. It is advisable to clarify in advance who will handle the report if the worst comes to the worst and how the process is to be documented.
Kali365 illustrates an unpleasant trend in the field of cybercrime: attackers are no longer just looking for classic security vulnerabilities but are deliberately abusing legitimate functions of trusted services. The attack, rented out via phishing-as-a-service, makes it easy even for less skilled criminals to specifically take over Microsoft 365 accounts – and it undermines of all things the multi-factor authentication that many companies rely on.
Because there is no easy patch, your most important protection lies in two things: educating your employees and carefully configuring your Microsoft 365 environment. The central message that everyone in your company should internalise is: never enter a login code that you did not request yourself – no matter how genuine the Microsoft page looks.
Ideally, check today, together with your IT manager, whether the device code login method can be restricted in your organisation, and raise your team's awareness. These few steps cost little time – but can prevent your company from becoming the next figures in a statistic that grows week by week.
Source: The Hacker News, "Kali365 Weaponizes Microsoft…", published on 5 August 2026 (thehackernews.com).