On May 21, 2026, the FBI’s Internet Crime Complaint Center issued public service announcement I‑052126‑PSA about a phishing platform called Kali365. It is worth reading if you handle other people’s money, because it breaks the single control our industry has been leaning on hardest.

Kali365 is sold as a subscription on Telegram and first surfaced in April 2026. It ships with AI-generated phishing lures, campaign templates, a live dashboard for tracking targets, and the feature that matters: it captures Microsoft 365 OAuth tokens. Security firms including Arctic Wolf and Proofpoint documented hundreds of attacks in April alone, across manufacturing, education, government, insurance, financial services and healthcare in North America and Europe.

The important part in one line: Kali365 does not steal your password and does not intercept your MFA code. It gets you to hand over a live session instead — and a live session needs neither.

Key Takeaways
  • The FBI issued PSA I‑052126‑PSA on May 21, 2026 about Kali365, a phishing-as-a-service platform sold on Telegram.
  • It abuses Microsoft’s legitimate OAuth 2.0 device code flow to capture access and refresh tokens.
  • Because it takes a session rather than a credential, multifactor authentication does not stop it.
  • Once inside, attackers read mail, create hidden inbox rules and register their own devices — the exact setup for a misdirected closing wire.
  • The FBI’s primary fix is a Conditional Access policy blocking device code flow, not more user training.
  • For consumers nothing changes: never accept wiring instructions by email, and always call a number you sourced yourself.

How the Attack Actually Works

Microsoft’s device code flow exists for a good reason. It lets you sign in on something with no keyboard — a conference room display, a TV app — by showing a short code you type into a browser on your phone or laptop. It is a legitimate, documented part of OAuth 2.0.

Kali365 turns that convenience into the attack. Per the FBI’s PSA, the sequence runs:

  1. The lure. You receive an email that appears to be from Microsoft, containing a device code and instructions to visit a Microsoft verification page.
  2. The authorization. You go to the real Microsoft page — genuine URL, valid certificate, nothing out of place — and enter the code.
  3. The token capture. Entering that code authorizes the attacker’s device. Microsoft issues them OAuth access and refresh tokens for your account.
  4. Persistence. They now reach Outlook, Teams and OneDrive with no password and no further MFA challenge. The refresh token keeps that access alive.

Notice what never happens. Nobody types your password into a fake page. Nobody asks you to read out a code from your authenticator app. There is no lookalike domain to catch, because you were on Microsoft’s actual site the entire time. You completed MFA correctly — and in completing it, you approved them.

That is why the standard advice fails here. “Check the URL” does not help when the URL is real. “Turn on MFA” does not help when MFA is the thing issuing the token.

Why Title and Escrow Is a Natural Target

The FBI’s PSA does not name specific industries, and Kali365 is not a title-industry tool. But consider what mailbox access is worth inside a real estate transaction and the appeal becomes obvious.

A compromised email account at a title agency, brokerage or lender hands an attacker three things at once: the transaction calendar, so they know exactly when funds move; the relationships, so they know which name the buyer already trusts; and the thread itself, so a fraudulent wire instruction arrives inside a conversation that has been running for weeks.

Reported Kali365 behavior after compromise matches that playbook precisely. Attackers accessed mailboxes, created malicious inbox rules — the classic move being a rule that files or deletes anything mentioning “wire,” “payoff” or “closing” so the real party never sees the correction — and registered unauthorized devices to hold access after cleanup.

Wire fraud in a real estate closing is rarely a technical break-in. It is almost always someone reading email they should not have and waiting for the right moment. Kali365 is a cheaper, faster way into that email.

What Clients Say

Trusted for Florida Closings

★★★★★

“Atlantic Title made our first home purchase so smooth. They explained every document clearly and closed on time. Couldn’t recommend them more highly.”

MR
Maria R.
First-Time Homebuyer
★★★★★

“As a Realtor I send every single client to Atlantic Title. Their team is responsive, professional, and always closes on time. My go-to title company in Florida.”

JT
James T.
Licensed Realtor
★★★★★

“We did a RON closing from out of state and it was absolutely seamless. The technology was easy to use and the team walked us through every step. Exceptional.”

SB
Sarah B.
Remote Buyer
$1 Billion+
In Closings
60+
Licensed Agents
67
Florida Counties
15+
Years of Excellence
For Realtors & Mortgage Loan Originators
Make your own co-branded marketing — free
A free self-serve tool — add your photo, logo & info and generate your own branded net sheets, flyers & payment breakdowns in seconds.
Create yours →

What the FBI Recommends

Notably, the FBI’s mitigations are administrative rather than educational. From the PSA:

  • “Create a conditional access policy to block device code flow for all users, with limited exceptions for required business processes.”
  • Audit existing device code flow usage in your tenant.
  • Block authentication transfer policies to prevent users from transferring authentication from computers to mobile devices.”
  • Exclude emergency access accounts from the restriction so you do not lock yourself out.

If you run Microsoft 365 and nobody at your company has looked at device code flow, that is the action item. Most title agencies and brokerages have no legitimate use for it at all, which makes blocking it a low-cost change.

For detecting an existing compromise, the PSA points to reviewing phishing emails with full headers, suspicious logins by time, IP and location, and unauthorized devices or active sessions — that last one being what most cleanup efforts miss. Resetting a password does not revoke a stolen refresh token. The session has to be revoked and the rogue device removed.

What This Changes at the Closing Table

Honestly? For the disbursement itself, very little — and that is the point worth making.

The controls that actually stop a misdirected wire were never email-based. A verified outbound callback to a number sourced independently of the instruction still works whether or not the sender’s mailbox is compromised, because it does not trust the mailbox. Dual authorization on large disbursements still works. Refusing to act on any change to wiring instructions without a live voice conversation still works.

If you are a buyer or seller rather than a title professional, the practical version of all this lives in our guide to wire fraud at a Florida closing — same defenses, written for the person sending the money.

What Kali365 should change is your confidence in email as evidence of anything. A message can arrive from the correct address, in the correct thread, with the correct signature, from a genuinely authenticated session — and still be written by someone else. If your process treats “it came from their real email” as verification, that process now has a hole in it.

At Atlantic Title Firm, every disbursement of $5,000 or more is verified by an answered outbound call to a number confirmed through an independent source, and no new or changed wire, payoff or disbursement instruction is acted on without one — regardless of the amount or how convincing the email looks. If you have a file with us and want to confirm you are looking at the right instructions, use our wire instruction verification page and call the number listed there.

If You’re Buying or Selling a Home in Florida

The practical guidance has not changed, and it does not require you to understand any of the above:

  • Assume every emailed wiring instruction is fraudulent until you have confirmed it by phone.
  • Get the number yourself — from the signed contract, the company’s website or a business card. Never from the email containing the instructions, and never from a link inside it.
  • Treat any change as a red flag. Legitimate closing instructions rarely change. “Our bank account has been updated” is the single most common line in real estate wire fraud.
  • Call your bank immediately if you suspect a misdirected wire. Recovery odds fall sharply after the first 24 to 72 hours.
  • Report it to the FBI at ic3.gov and tell your closing agent right away.
  • Read the full consumer walkthroughwire fraud at a Florida closing, including what recovery actually looks like.
Forms & Documents

Open & Move Your File Online

Already have a signed contract? Send it over and we’ll open your file today.

Submit a Contract →

See all forms & documents →

Related Reading

Frequently Asked Questions

What is Kali365?

Kali365 is a phishing-as-a-service platform sold by subscription on Telegram, first observed in April 2026. It provides AI-generated phishing lures, campaign templates, target-tracking dashboards and the ability to capture Microsoft 365 OAuth tokens. The FBI issued public service announcement I-052126-PSA about it on May 21, 2026.

How does Kali365 get past multifactor authentication?

It does not defeat MFA so much as go around it. The attack abuses Microsoft’s legitimate OAuth 2.0 device code flow: the victim receives a device code by email, enters it on the genuine Microsoft verification page, and in doing so authorizes the attacker’s device. Microsoft then issues OAuth access and refresh tokens. Because the attacker holds a valid session rather than a password, no further MFA challenge occurs.

Does changing my password fix a Kali365 compromise?

Not on its own. A stolen refresh token remains valid after a password reset. Remediation requires revoking active sessions and tokens, removing any unauthorized registered devices, and reviewing the mailbox for malicious inbox rules the attacker may have created.

What should a title agency or brokerage do about it?

The FBI’s primary recommendation is a Conditional Access policy blocking device code flow for all users, with limited exceptions, plus auditing existing device code usage and blocking authentication transfer policies. Most title agencies have no legitimate business use for device code flow, which makes blocking it a low-cost change. Emergency access accounts should be excluded so you do not lock yourself out.

Are emailed wiring instructions ever safe?

No, and that was true before Kali365. Wiring instructions should always be confirmed by an answered phone call to a number obtained independently — from the signed contract, the company’s website or a business card — never from the email containing the instructions or a link inside it.

What do I do if I think a wire went to the wrong place?

Call your bank immediately and ask them to initiate a SWIFT recall or hold, notify your closing agent, and file a report with the FBI at ic3.gov. Recovery chances drop sharply after the first 24 to 72 hours, so speed matters more than certainty — report it even if you are not sure yet.