All Articles

Cyber Security · September 2026

When your staff signs in correctly and attackers still get in

A new style of phishing doesn't steal passwords. It tricks your team into authenticating a session that belongs to someone else.

Your team has been trained to spot fake login pages. You run multifactor authentication. And yet there is now a style of phishing that sidesteps both. The Kali365 phishing kit, active since early 2026 and reported by the FBI in May, does not ask anyone to type a password into a fake form. It asks them to complete a real Microsoft sign-in that hands access to an attacker. Because the login page is genuine and MFA works as expected, many of the warning signs you rely on no longer appear.

What actually happens

Someone in your office receives an email that looks like a shared file link, a voicemail notification, an electronic signature request, or a mailbox storage alert. They click. They are asked to verify their identity by entering a short code at a Microsoft device login page. The page is real. The code works. They sign in with their actual password and approve the MFA prompt on their phone.

What they do not see is that the code they entered was generated by an attacker. When they signed in, they authenticated a session the attacker controls. Minutes later, that attacker has access to email, SharePoint files, Teams conversations, and OneDrive folders. No password was stolen. No fake page was built. The person who signed in did exactly what Microsoft asked them to do.

This is called device code phishing, and it works because it abuses a legitimate feature that Microsoft built for connecting apps and devices to your account.

Why this matters for Ontario businesses right now

Most small and mid-sized businesses in Ontario run Microsoft 365. Most have turned on MFA in the past two years. Many believe that combination is enough to stop phishing. It is not.

Device code phishing does not try to bypass MFA. It uses it. The attacker does not need to crack a password or trick a user into typing credentials into a fake site. They only need to convince someone to complete a routine verification step that feels identical to legitimate work.

If your business uses Microsoft 365 and your team regularly clicks links to shared documents, invoice PDFs, or mailbox notifications, this attack can reach you. It does not require a targeted campaign or advanced research. Kali365 is sold as a service, so any buyer can run it.

What you should watch for

Because the authentication happens on Microsoft's real login page, your usual email filtering and link reputation tools may not catch it. You need to watch what happens after someone signs in.

Unexpected device registrations are one signal. If your audit logs show new devices appearing in your tenant after an email link is clicked, that is worth investigating. Mailbox rules that forward email externally or move messages to obscure folders are another. Unusual access to SharePoint, OneDrive, or Teams from unfamiliar locations or IP addresses is a third.

None of these signals is definitive on its own, but together they point to a compromised session. The problem is that most small businesses do not have anyone watching these logs day to day. That is where the gap sits.

What is worth doing on Monday

Start by checking whether your Microsoft 365 tenant logs authentication events and tracks device registrations. If you are not logging sign-ins and device activity, you will not be able to detect this style of attack after it happens.

Next, review your conditional access policies. Microsoft allows you to block device code authentication entirely if your business does not need it for legitimate workflows. If no one in your office is using device code login for apps or hardware, turning it off removes the risk.

If you do need device code authentication, you can restrict it to trusted locations or managed devices. This will not stop every attack, but it raises the bar.

Finally, talk to your team about what verification requests should look like. If someone receives an email with a link and then sees a request to enter a short code at a Microsoft page, that is worth a second look. Not every code prompt is an attack, but the pattern is now common enough that it should trigger a question.

What is not worth worrying about yet

This is not a reason to abandon MFA or assume your current defences are useless. MFA still stops the majority of credential theft attacks. Device code phishing is harder to pull off than a fake login page, and it requires the attacker to time the session correctly.

It is also not a reason to assume your business has already been compromised. While Kali365 has been active since early 2026, it remains one kit among many, and most phishing still uses simpler methods.

What has changed is that password security alone is no longer enough. You need visibility into what happens after your team signs in. If you do not have someone monitoring authentication logs, mailbox rules, and device registrations, that is the gap to address first.

Sources

See our security services

Get started today

Have an IT Question?

Our team is ready to help, whether you need advice on cybersecurity, cloud strategy, or AI readiness.