You can force a password reset across the company tonight. If an attacker already holds a valid session token, that reset changes nothing. The application already trusts the session.
On 21 May 2026, the FBI Internet Crime Complaint Center issued a public warning about a Phishing-as-a-Service platform named Kali365. The victim completes a genuine Microsoft login and a real MFA prompt. Everything looks normal from their side. The operator still walks away with persistent access.
No password is intercepted. MFA is satisfied. Your logs stay clean.
That last part is the problem. Most security teams are waiting for an alert that will never fire, because the exploitation step does not produce one.
We broke down how these kits work, why your email gateway and your SIEM are both blind to them, what the underground market pays for a live corporate session, and the four controls that actually reduce the surface.
Read it here: Phishing-as-a-Service (PhaaS): Your session is for sale