
If your insurance agency uses Microsoft 365, the recent FBI warning about Kali365 is worth paying attention to.
On May 21, 2026, the FBI’s Internet Crime Complaint Center issued a public warning about Kali365, a phishing platform that targets Microsoft 365 users through a device code login process. This is not the old style of phishing where someone simply steals a password from a fake login page.
This attack is more subtle.
The user is directed to a real Microsoft verification page and asked to enter a device code. Because the page is legitimate, the user may assume the request is safe. In reality, they may be authorizing an attacker’s device to access their Microsoft 365 account. Once that happens, the attacker can capture access tokens and gain access to services like Outlook, Teams, and OneDrive without needing the user’s password in the traditional sense.
That distinction matters.
Many businesses still think about cybersecurity in terms of passwords and multifactor authentication. Those controls are still important, but they are not the whole story anymore. In this type of attack, the user can be tricked into approving access through a legitimate Microsoft process.
For an insurance agency, that is a serious operational risk.
Microsoft 365 is not just email. In most agencies, it is where client communication happens, where renewal documents are exchanged, where internal conversations take place, where producers and service teams coordinate, and where sensitive business records may be stored or shared.
If Outlook is compromised, agency communication is compromised.
If OneDrive or SharePoint is compromised, agency documents may be exposed.
If Teams is compromised, internal conversations and business decisions may be visible to someone who should not be there.
This is why the Kali365 warning should not be treated as just another cybersecurity headline. It is a reminder that Microsoft 365 has to be properly secured, governed, and monitored.
Having Microsoft 365 is not the same as having Microsoft 365 properly protected.
At a minimum, agency leaders should have four areas reviewed in the agency’s Microsoft 365 environment.
First, review device code flow.
In many Microsoft 365 environments, device code flow may be allowed simply because nobody made a deliberate decision to restrict it. That is not governance. That is default exposure. Agencies should review whether this feature is actually needed, where it is being used, and whether it can be blocked or limited.
Second, review Conditional Access policies.
Conditional Access is one of the most important security controls in Microsoft 365. It can help determine when access is allowed, from what locations, on what devices, and under what conditions. If these policies are missing, weak, or too broad, the agency may be relying too heavily on basic login protection.
Third, review OAuth and application approvals.
Attackers increasingly look for ways to gain access through approvals, tokens, sessions, and connected applications. Agencies should know who can approve apps, what apps already have access, and whether risky or unnecessary permissions have been granted.
Fourth, update staff training.
Traditional security awareness training often focuses on fake login pages, suspicious links, and bad attachments. That is still useful, but incomplete. Staff also need to understand that a real Microsoft page can still be part of an attack if they are being tricked into entering a code or approving access they did not initiate.
A practical rule is simple:
If a CSR, producer, account manager, or executive is asked to enter a Microsoft code to connect, verify, or approve something they did not personally start through a known business process, they should stop and report it.
This does not mean agency owners need to become cybersecurity engineers.
It does mean agency leadership should be asking better questions.
- Is device code flow allowed in our Microsoft 365 tenant?
- Do we actually need it?
- Are exceptions documented?
- Are Conditional Access policies in place?
- Are risky app approvals restricted?
- Do we monitor suspicious sign ins, unusual token behavior, and unexpected device activity?
- Do our users know that approving access can be just as dangerous as entering a password?
These are not theoretical questions. They are practical business questions.
Insurance agencies run on trust, communication, documentation, and responsiveness. When Microsoft 365 is compromised, the impact is not limited to IT. It can affect client service, carrier relationships, internal operations, financial discussions, compliance responsibilities, and leadership time.
The right answer is not panic.
The right answer is review, tighten, document, monitor, and train.
For most agencies, the key is not simply whether Microsoft 365 is in place. It is whether the environment has been configured with intention. Device code flow, Conditional Access, app approvals, user training, alerting, and monitoring all need to work together.
Cybersecurity is no longer just about having tools. It is about making sure the tools, policies, settings, monitoring, and training are aligned with how the agency actually operates.
The FBI warning on Kali365 is a good reminder of that.
Insurance agencies rely heavily on Microsoft 365 every day. Email, Teams, OneDrive, SharePoint, client communication, internal workflows, carrier conversations, and renewal activity all depend on it. That makes Microsoft 365 security a business issue, not just a technical setting buried in the admin portal.
Agencies that have not recently reviewed these areas should treat this as a good reason to take a closer look.
References
- FBI Internet Crime Complaint Center, Kali365 Phishing as a Service Kit Hijacks Microsoft 365 Access Tokens, May 21, 2026.
- Microsoft Learn, Block authentication flows with Conditional Access policy, last updated April 7, 2026.
- Microsoft Security Blog, Inside an AI enabled device code phishing campaign, April 6, 2026.
About Jerry Fetty
Jerry Fetty is the Founder of SMART Services and has spent 35+ years helping independent insurance agencies modernize their technology, strengthen cybersecurity, and operate more efficiently. Today, his focus is helping agencies adopt AI the right way, with a secure foundation, clean data structure, clear policies, and real world training that produces measurable ROI.