47 million pounds. That is what Britain’s tax authority says organised criminals extracted after using stolen personal data and phishing to impersonate taxpayers. The FBI warned on May 21, 2026 that a rapidly spreading kit called Kali365 can capture OAuth device codes and refresh tokens, letting attackers keep long-term access to Microsoft 365 accounts without stealing passwords. U.S. and European agencies, plus security firms including Norton, say the new mechanics force businesses and individuals to change how they block and report phishing.
Because Kali365 captures OAuth device codes and refresh tokens, the typical password-and-MFA narrative no longer guarantees safety. The FBI advisory describes a shift: instead of tricking victims into handing over credentials, attackers direct targets to paste device codes into Microsoft’s real verification page. Once a victim follows the prompt, the attacker harvests tokens that bypass multi-factor authentication and deliver persistent access to Outlook, Teams and OneDrive accounts.
The FBI said Kali365, identified in April 2026 and circulating on Telegram, is being marketed as phishing-as-a-service. The kit bundles AI-written lure emails, ready-made templates, a live dashboard and tools to harvest OAuth tokens. That package turns what used to be a skilled operation into a buy-and-deploy crime, letting inexperienced actors run targeted campaigns with little technical know-how.
Norton, the security unit of Gen Digital, found attackers pairing scraped or stolen personal information with those realistic lures to create highly targeted spear-phishing messages. Luis Corrons, who led Norton’s analysis, said attackers were repurposing legitimate hotel reservation details and other booking information to make messages convincing. Norton catalogued at least 350 accommodations across 50 countries used in reservation-hijacking scams, where attackers built bespoke sites that asked for payment or card details.
The result is more than a new trick. Token harvesting subverts common defenses. Tokens grant sessions and refresh privileges without presenting a password. That means automated systems that flag unusual password changes or MFA failures may not see the misuse, and stolen tokens can persist until revoked or expired.
Real losses, and practical steps authorities recommend
Phishing campaigns have already produced significant financial harm. HM Revenue and Customs told lawmakers organised criminals used personal information gathered through phishing or other means to submit fraudulent payment claims and extract 47 million pounds.
The agency said it had locked affected accounts and corrected records and that those affected didn't suffer personal financial loss after remediation.
In Ireland the National Treasury Management Agency reported a separate incident in which a payment of 5 million euros went to what staff believed was an investee company but was instead a fraudulent request designed to look legitimate. NTMA Chief Executive Frank O’Connor said investigators would look hard at internal systems and protocols. Finance Minister Paschal Donohoe called the attack regrettable but extremely rare. Both agencies reported incidents to police and said they're seeking to recover funds.
Regulators and security companies are offering concrete mitigations. The FBI advised businesses to change network settings to block or limit quick device-linking codes and to disable settings that allow easy transfer of logins between devices. The agency asked victims to file complaints and to supply email headers, suspicious login times, IP addresses and details of unauthorized sessions to aid investigations.
The Federal Trade Commission warned consumers about a wave of "You’re Invited" scams that mimic invitation platforms and ask recipients to enter email usernames, passwords or phone codes to view an event. The FTC recommends keeping security software up to date, using two-factor authentication where available, verifying unexpected invitations with the host by separate contact methods, and changing account passwords immediately if compromise is suspected.
Security vendors emphasize blocking device-code flows where doable and treating unexpected reservation confirmations, booking changes or event invitations with heightened suspicion. Norton’s research shows attackers increasingly stitch victims’ real booking names, dates and confirmation numbers into fraudulent messages, making social engineering far more convincing than generic phishing spam.
Investigations and recovery efforts are underway across jurisdictions. HM Revenue and Customs said it had locked affected accounts and corrected records, and the NTMA and other agencies reported the incidents to police and are pursuing recovery. Meanwhile, the FBI and the FTC have published reporting procedures and mitigation advice for businesses and consumers.
For organizations that manage large numbers of accounts, the practical work involves revoking tokens, tightening device-linking policies and auditing session logs. For individuals the task is simpler but urgent: verify unexpected requests through a separate channel, update passwords and security settings, and report suspicious messages to platform providers and law enforcement.
Phishing remains a broad category of fraud. It covers deceptive messages designed to trick people into revealing credentials, authorizing access or clicking malicious links. Kali365 is only the latest example of how criminals adapt to defensive changes, combining automation, AI-generated lures and harvest tools to scale targeted attacks.
Related Articles
- 3 Options for IoT Test Data and Which to Use
- AI video interviews scale hiring but accept nonsense as fit
- Automate file renaming with AI
Authorities are urging victims to file complaints and to supply email headers, suspicious login times and IP addresses so investigators can trace and revoke harvested sessions.
This article was created with AI assistance.