Even with MFA enabled, phishing attacks may still bypass account protection. Cybercriminals may impersonate cloud services, shared file notifications, or collaboration platforms to trick users into entering a device code and granting access to their accounts.
According to the FBI IC3 Public Service Announcement issued on May 21, 2026, the Kali365 phishing-as-a-service platform has been used to target Microsoft 365 accounts. Attackers may pretend to be legitimate Microsoft or cloud service notifications and lure users into entering a device code. Once access is granted, services such as Outlook, Teams, and OneDrive may be compromised.
Password + MFA ≠ Absolute Security.
Always verify before granting access.