• Skip to primary navigation
  • Skip to main content
Dean Dorton – CPAs and Advisors
  • Services
        • Audit & Assurance
          • Audits, Reviews & Compilations
          • ESG Programs & Reporting
          • Internal Audit
          • International Financial Reporting
          • Lease Accounting Managed Services
          • Peer Review Services
          • SOC Reporting
        • Family Office
        • Consulting & Advisory
          • Business Valuation Services
          • Forensic Accounting
          • Fractional CFO
          • Litigation Support
          • Matrimonial Dissolution
          • Merger & Acquisition
          • SEC Services
          • Succession Planning
          • Transaction Advisory Services
          • Whistleblower Hotline
        • Outsourced Accounting
        • Private Wealth
        • Healthcare Consulting
          • Finance
          • Health Systems Operational Transformation
          • Medical Billing and Credentialing
          • Risk Management & Compliance
          • Strategic Growth for Private Practices
          • Strategy and Strategy Implementation
          • Technology & Data Analytics
        • Tax
          • Business Tax
          • Cost Segregation Studies
          • Credits and Incentives
          • Estates and Trusts
          • Individual Tax
          • International Tax
          • SEC Provision and Compliance
          • State and Local Tax
        • Technology & Cybersecurity
          • Accounting Software
          • Cybersecurity, IT Audit, & Compliance
            • Cybersecurity Assessments
            • Cybersecurity Maturity Model Certification (CMMC)
            • Cybersecurity Scorecard Assessment
            • Data Privacy Laws
            • Security Awareness Training
            • SOC Reporting
            • Virtual Information Security Office
          • Data Analytics & AI
          • IT Infrastructure & Cloud Solutions
            • Automation
            • Backup and Disaster Recovery
            • Cloud Strategy
            • Data Center
            • Enterprise Network
            • Network Security
            • Phone and Video Conferencing
            • User Identity Management Solutions
            • Webex
          • Managed IT Services
  • Industries
        • Construction
        • Distilleries and Craft Breweries
        • Energy and Natural Resources
        • Equine
        • Financial Institutions
        • Government
        • Healthcare
        • Higher Education
        • Life Sciences
        • Manufacturing and Distribution
        • Nonprofit
        • Real Estate
  • Insights
    • Articles
    • Guides
    • Case Studies
  • Events
  • Company
        • News
        • Our Team
        • Experiences
        • Careers
          • College Students
          • Experienced Professionals
        • Locations
        • Lexington, KY

          250 West Main Street
          Suite 1400
          Lexington, KY 40507
          859-255-2341

        • Louisville, KY

          435 North Whittington Parkway
          Suite 400
          Louisville, KY 40222
          502-589-6050

        • Louisville, KY

          700 North Hurstbourne Parkway
          Suite 115
          Louisville, KY 40222
          502-589-6050

        • Ft. Wright, KY

          810 Wright’s Summit Parkway
          Suite 300
          Fort Wright, KY 41011
          859-331-3300

        • Cincinnati, OH

          312 Walnut Street
          Suite 3330
          Cincinnati, OH 45202
          859-331-3300

        • Blue Ash, OH

          9987 Carver Rd
          Suite 120
          Blue Ash, OH 45242
          513-891-5911

        • West Chester, OH

          9025 Centre Pointe Drive
          Suite 310
          West Chester, OH 45069
          513-985-6240

        • Indianapolis, IN

          5975 Castle Crk Pkwy Dr N
          Suite 400
          Indianapolis, IN 46250
          317-469-0169

        • Raleigh, NC

          4130 Parklake Avenue
          Suite 400
          Raleigh, NC 27612
          919-782-9265

  • Contact Us

cyber attack

Article 06.17.2026 Danielle Camara

For years, the cybersecurity community has championed multi-factor authentication (MFA) as the single most impactful control organizations can implement to protect their accounts. And that guidance remains sound, but it comes with a critical caveat: not all MFA is created equal, and attackers have found ways around it.

The FBI issued an urgent Public Service Announcement in May 2026 warning about a new Phishing-as-a-Service (PhaaS) platform called Kali365 that is specifically engineered to bypass MFA in Microsoft 365 environments, without ever stealing your password.

This is a threat your organization needs to understand and act on now.

What Is Kali365 and Why Should You Care?

Kali365 is a subscription-based attack toolkit distributed through Telegram that enables cybercriminals (even those with limited technical skills) to compromise Microsoft 365 accounts at scale. Its capabilities include AI-generated phishing lures, automated campaign management, real-time victim tracking dashboards, and most dangerously, OAuth token capture.

What makes Kali365 particularly alarming is the attack method it exploits: device code flow phishing. This technique abuses a legitimate Microsoft authentication mechanism, allowing attackers to hijack a user’s authenticated session entirely by bypassing the MFA process.

How the Attack Works

The attack chain is deceptively simple and exploits user trust in Microsoft’s own infrastructure:

  • Lure – A victim receives a phishing email impersonating a familiar cloud service (think DocuSign, SharePoint, or Microsoft Teams). The email contains a device code and instructs the recipient to visit a legitimate Microsoft verification page to enter it.
  • Authorization – The victim navigates to a real Microsoft URL (microsoft.com/devicelogin) and enters the code. Because the page is genuine, nothing looks suspicious. The victim may also complete an MFA prompt at this stage believing they are authenticating into a trusted service.
  • Token Theft – In the background, the attacker’s device captures the resulting OAuth access token and refresh token. These tokens represent a fully authenticated session as no password required, and no further MFA is needed.
  • Persistent Access – With valid tokens in hand, the attacker gains access to Outlook, Teams, OneDrive, SharePoint, and other Microsoft 365 services. Refresh tokens can extend this access for days or weeks.

The victim completed MFA. The victim did nothing obviously wrong and the attacker now owns the account.

Why This Bypasses MFA

Traditional MFA protects the password login flow. Device code flow phishing sidesteps that flow entirely. The attacker is not trying to log in as you but instead tricking you into authorizing their device through a legitimate Microsoft interface. When the MFA prompt is complete, it is validating the attacker’s session, not protecting against it.

This is why the FBI’s advisory specifically warns that standard MFA protocols are insufficient against this attack vector, and why organizations relying solely on SMS codes, authenticator app push notifications, or even TOTP codes remain exposed.

Who Is at Risk?

Any organization using Microsoft 365 is potentially vulnerable if device code flow authentication is enabled, which is by default in most tenant configurations. Industries handling sensitive data or subject to regulatory oversight face compounded risk:

  • Healthcare organizations – PHI exposure, HIPAA breach notification obligations
  • Financial services firms – client data, wire transfer systems, fiduciary exposure
  • Professional services – confidential client communications, privileged information
  • Manufacturing and supply chain – operational systems accessible through M365 identities
  • Higher education – FERPA-protected student records, research data

The broad availability of Kali365 through a low-cost Telegram subscription means even organizations that are not high-profile targets may be swept up in opportunistic campaigns.

What Your Organization Should Do

The FBI and Dean Dorton recommend the following immediate and near-term actions:

Immediate Priority: Restrict Device Code Flow

The core technical mitigation is to disable or restrict device code flow authentication in your Microsoft Entra ID (formerly Azure AD) environment through Conditional Access policies.

  • Audit first – Before blocking device code flow broadly, identify any legitimate business processes that rely on it (certain legacy devices, printers, or kiosk scenarios may use it). Blocking without auditing can cause disruptions.
  • Create a Conditional Access policy – To block device code flow for all users, with documented exceptions for verified legitimate use cases.
  • Protect emergency access accounts – Exclude your break-glass accounts from this policy to prevent an accidental lockout scenario.
  • Block authentication transfer – Implement policies that prevent authentication sessions from being transferred between devices.

Upgrade to Phishing-Resistant MFA

Against this attack technique, phishing-resistant MFA is not a complete defense because Device Code Phishing can trick a user into authorizing access through a legitimate device-code flow. However, it provides exceptional protection against Adversary-in-the-Middle phishing by binding authentication to the legitimate website or service, preventing stolen credentials or session interactions from being replayed through a proxy. It also significantly reduces the effectiveness of targeted vishing attacks, since attackers cannot simply persuade users to reveal a one-time code, approve a push notification, or share a password-equivalent factor.

Your organization should evaluate and migrate toward phishing-resistant authentication methods, including:

  • FIDO2 / Passkeys – Hardware or platform-bound authenticators that cryptographically bind authentication to the legitimate site
  • Certificate-Based Authentication (CBA) – Smart cards or device certificates that cannot be proxied
  • Windows Hello for Business – Windows Hello for Business is a phishing-resistant MFA method that replaces passwords with device-bound cryptographic keys, so authentication succeeds only from the enrolled device using the user’s biometric gesture or PIN.

Train Your Users With This Specific Scenario

Device code phishing succeeds in part because users are trained to complete MFA prompts. Update your security awareness training to include:

  • What device code flow authentication looks like
  • The rule: never enter a code on Microsoft’s device login page unless you personally initiated the sign-in from a known device
  • Skepticism toward any email requesting authentication through an unfamiliar workflow

Monitor for Indicators of Compromise

If you have a SIEM, MDR, or Microsoft Defender for Identity in place, configure alerting for:

  • OAuth token grants from unexpected IP addresses or geographies
  • Sign-ins during unusual hours tied to token-based authentication
  • Unusual access patterns to Teams, OneDrive, or SharePoint following a device code flow event
  • Active sessions originating from IP addresses not associated with known users

Review Third-Party App Permissions

Attackers with valid OAuth tokens can also grant persistent access to malicious third-party applications. Audit your Microsoft 365 tenant for:

  • Unexpected OAuth application consents
  • Apps with broad permissions (Mail.Read, Files.ReadWrite.All) granted by end users
  • Applications you do not recognize in the Enterprise Applications list

How Dean Dorton Can Help

Our Cybersecurity Risk & Compliance team works with organizations across all industries including healthcare, financial services, manufacturing, and professional services to assess and strengthen Microsoft 365 security postures. Specific services relevant to this threat include:

  • Microsoft 365 Security & Tenant Assessment – A comprehensive review of your Entra ID configuration, Conditional Access policies, MFA posture, and OAuth application inventory
  • Phishing-Resistant MFA Advisory – Evaluating and planning a migration from legacy MFA methods to FIDO2 or certificate-based authentication
  • Managed Detection & Response (MDR) – 24/7 monitoring for identity-based threats, including token abuse and anomalous sign-in activity
  • Security Awareness Training – Updated training content that incorporates emerging social engineering techniques like device code phishing
  • Fractional CISO Services – Ongoing strategic guidance for organizations that need expert cybersecurity leadership without a full-time hire

The Bottom Line

The Kali365 advisory is a timely reminder that attackers adapt faster than most organizations update their defenses. MFA is still a critical control. However, the threat landscape has evolved, and organizations that deployed MFA several years ago and never revisited their authentication architecture are not as protected as they believe.

Restricting device code flow and migrating to phishing-resistant MFA are not long-term roadmap items. They are actions that should be prioritized today.

If you would like to discuss your organization’s Microsoft 365 security posture or schedule an assessment, contact the Dean Dorton Cybersecurity Risk & Compliance team.

Reference: FBI IC3 Public Service Announcement I-052126-PSA, “Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokens,” May 21, 2026. https://www.ic3.gov/PSA/2026/PSA260521

Filed Under: Cybersecurity, Technology Tagged With: cyber attack, Cybersecurity, Kali365, Microsoft 365

Article 10.7.2019 Dean Dorton

For small businesses, the result of a cyber incident can be disastrous. While larger organizations and enterprises may be able to absorb the monetary costs and reputational damage that is caused by a cyber incident, most smaller businesses are unable.

“The National Cyber Security Alliance has recently released statistics that show 20% of small businesses experience such an attack every year, and that 60% of these businesses were forced to close within six months of being hacked.”1

Cybersecurity risks are constantly evolving as organizations adopt new technology (such as cloud services) and cyber criminals adopt new tactics, techniques, and procedures (TTPs). The construction industry doesn’t have the same regulatory and compliance requirements pertaining to cybersecurity that other industries—such as the financial and healthcare sectors—have, yet they face the same threats. For this reason, it is imperative for the construction industry to focus on cybersecurity risks to avoid becoming the next victim of cybercrime.

How a Cybersecurity Attack Can Impact Construction Companies

Today, construction companies transmit and store the kinds of sensitive data that cyber criminals target most. Employee and project information, contracts, financial data, and planning tools are all at risk — yet the industry remains behind the curve in bolstering cyber security measures compared to other industries. 

What’s more, the move to an increasingly remote workforce with more devices in play has exposed gaps in networks that cyber criminals are all too happy to exploit. And as the industry continues to embrace the Internet of Things (IoT) and leverage artificial intelligence technologies, their potential attack surface also continues to expand.

Cyber criminals most often seek financial gain from an attack via ransomware. But there are additional, deeper impacts of a cyber attack as well:

  • Down time: Deadlines aren’t made to be broken. An interruption in business due to a technology disruption can cost a company days or even weeks it can’t afford in reduced or even lost productivity.
  • Breach of project IP: Loss of privileged contracts, proprietary designs, schematics, and confidential blueprints can not only lead to huge financial losses. It could also result in irreparable damage to reputation.
  • Loss of bid information: Forfeiting leverage in the upfront process can result in losing competitive advantage, as well as the job itself.
  • Equipment damage: It’s a concern for equipment off and on site. Servers, devices, and key computing hardware are costly to repair or replace. And compromised on-site equipment can lead to significant physical damage to nearby structures and the equipment itself.
  • Workforce injuries: Protecting the most valuable asset is paramount. A security breach or system failure that allows autonomous equipment to be compromised puts the safety of workers — and civilians — at significant risk.  

There are many ways that cybercriminals (also known as threat actors) can compromise confidential information in an organization. Below, we’ll address three of the most common vectors for a successful cyber attack.

Common Cybersecurity Threats for Construction Companies:

Spear Phishing

One of the most common techniques, “spear phishing is an email targeted at a specific individual or department within an organization that appears to be from a trusted source. It’s actually cybercriminals attempting to steal confidential information. A whopping 91% of cyberattacks and the resulting data breach begin with a spear phishing email, according to research from security software firm Trend Micro. This conclusively shows that users really are the weak link in IT security.”2

Often, threat actors will employ the use of malicious file attachments when conducting these types of attacks. “There are many options for the attachment such as Microsoft Office documents, executables, PDFs, or archived files. Upon opening the attachment (and potentially clicking past protections), the adversary’s payload exploits a vulnerability or directly executes on the user’s system. The text of the spear phishing email usually tries to give a plausible reason to open the file, and may explain how to bypass system protections in order to do so. The email may also contain instructions on how to decrypt an attachment, such as a zip file password, in order to evade email boundary defenses. Adversaries frequently manipulate file extensions and icons in order to make attached executables appear to be document files, or files exploiting one application appear to be a file for a different one.”3

Password Spraying

This technique “uses one password (e.g. Password01), or a small list of passwords, that matches the complexity policy of the domain and may be a commonly used password. Logins are attempted with that password and many different accounts on a network to avoid account lockouts that would normally occur when brute forcing a single account with many passwords.” For instance, from September 2018 through February 2019, Proofpoint conducted a six-month study that analyzed over 100,000 unauthorized logins across millions of monitored cloud user-accounts.”4

“The company found that 60% of Microsoft Office 365 and G Suite tenants were targeted with IMAP-based password-spraying attacks, while 25 percent were successfully breached in this manner. Proofpoint noted that the number of IMAP-based password-spraying attacks jumped up following the December 2018 publishing of the Collection #1 data dump that exposed nearly 773 million unique emails and 21 million unique passwords.”5

Exploiting Vulnerabilities in Unpatched Software

“Earlier this year, the National Security Agency urged organizations to ensure that they are using patched and updated systems in the face of growing threats. The vulnerability is present in Windows 7, Windows XP, Server 2003 and 2008, and although Microsoft has issued a patch, potentially millions of machines are still vulnerable.”6

How Construction Companies Can Mitigate Cybersecurity Risks

Dean Dorton recommends that organizations consider the following to identify their risks and enhance their cybersecurity preparedness:

  • Identify where your valuable information is stored (on your internal network and the cloud)
  • Develop policies, procedures, and standards pertaining to cybersecurity
  • Adopt a cybersecurity control framework
  • Develop a cybersecurity incident response plan
  • Secure your backups; also, test your backups to ensure they work correctly upon use
  • Disable legacy authentication protocols (such as IMAP)
  • Enforce two-factor authentication (2FA), also referred to as multi-factor authentication (MFA)
  • Update and patch your computers. Vulnerable operating systems and third-party applications are often targeted by threat actors. You should ensure that your operating systems and third-party applications are updated with the latest updates.
  • Train your organization. “Organizations should ensure that they provide cybersecurity awareness training to their personnel. Ideally, organizations will have regular, mandatory cybersecurity awareness training sessions to ensure their personnel are informed about current cybersecurity threats and threat actor techniques. To improve workforce awareness, organizations can test their personnel with phishing assessments that simulate real-world phishing emails.”7
  • Perform regular cybersecurity assessment and penetration tests against the network—no less than once a year. Ideally, run these as often as possible and practical. Dean Dorton can perform these tests for you.

Dean Dorton’s Information Security Office (ISO) provides a team of experienced information security professionals who can augment your organization’s information security team or take the lead in designing, implementing, and maintaining a strong information security program on your behalf.

1https://www.csoonline.com/article/3437777/how-a-small-business-should-respond-to-a-hack.html
2https://www.knowbe4.com/spear-phishing/
3https://attack.mitre.org/techniques/T1193/
4https://attack.mitre.org/techniques/T1110/
5https://www.scmagazine.com/home/security-news/password-spraying-attacks-abuse-imap-to-break-into-targets-cloud-accounts/
6 https://www.nsa.gov/News-Features/News-Stories/Article-View/Article/1865726/nsa-cybersecurity-advisory-patch-remote-desktop-services-on-legacy-versions-of/
7 https://www.us-cert.gov/ncas/tips/ST19-001

Filed Under: Construction, Cybersecurity, Industries, Services, Technology Tagged With: Construction, cyber attack, Cybersecurity, phishing, Technology

  • Services
    • Outsourced Accounting
    • Audit & Assurance
    • Tax
    • Consulting & Advisory
    • Technology & Cybersecurity
    • Family Office
    • Wealth Management
  • Industries
  • Company
  • Locations
  • Careers
  • Insights
  • Events
  • Contact Us
facebook Dean Dorton - CPAs And Advisors On Facebook twitter twitter linkedin Dean Dorton - CPAs And Advisors On LinkedIn youtube Dean Dorton - CPAs And Advisors On YouTube

The matters discussed on this website provide general information only. The information is neither tax nor legal advice. You should consult with a qualified professional advisor about your specific situation before undertaking any action.

© 2026 Dean Dorton Allen Ford, PLLC. All Rights Reserved