The rise of token-theft attacks: No password or MFA needed | TechTarget
Attackers can access Microsoft 365 accounts -- reaching Outlook, Teams and OneDrive -- without needing a password or completing MFA challenges. But how?
Using an emerging phishing-as-a-service platform called Kali365, which was first seen in April 2026, malicious hackers capture OAuth tokens and gain persistent access to targeted entities' Microsoft 365 environments.
"Kali365 lowers the barrier of entry, providing less-technical attackers access to AI-generated phishing lures, automated campaign templates, real-time targeted individual/entity tracking dashboards, and OAuth token capture capabilities," the FBI wrote in a May bulletin.
The FBI's warning came just months after another high-level incident involving token theft. In 2025, Google's Threat Intelligence Group reported that a threat actor targeted organizations using compromised OAuth tokens associated with Salesloft Drift, an application with Salesforce integrations that has since been sunsetted.
These two incidents prove that token theft remains a significant and adjustable cybersecurity threat. When bad actors steal session...
Copyright of this story solely belongs to techtarget.com. To see the full text click HERE