🚨 FBI Warns of OAuth Consent Phishing That Can Bypass Passwords and MFA
OFFICIAL GOVERNMENT WARNING — FBI / Internet Crime Complaint Center (IC3)
Report date: September 1, 2026
Scam type: OAuth consent phishing / account takeover / impersonation phishing
WHAT HAPPENED
The FBI’s Internet Crime Complaint Center issued a new public service announcement warning that malicious cyber actors are using OAuth consent phishing to gain access to victims’ accounts. The FBI says the activity has targeted prominent individuals, their family members, and personal acquaintances, often through direct messages containing malicious links.
HOW THE SCAM WORKS
The scammer impersonates a trusted person or role — such as a government official, journalist, media contact, event coordinator, or planner — and sends a link disguised as a file-sharing, invitation, or identity-verification request. The link can lead to a legitimate Google, Microsoft, or other provider sign-in and permission screen. The danger comes when the victim approves the requested permissions. Instead of stealing the password, the malicious app receives an authorization token that can allow access to email, files, and other data.
The FBI warns that this access can persist even after the victim changes a password. Because the malicious app was granted permission through the provider’s legitimate authorization process, the attacker may also bypass protections that consumers normally associate with passwords and multi-factor authentication. The harmful app or token must be revoked in the account’s security settings.
WHO IS BEING TARGETED
The current FBI warning describes prominent victims, their family members, and personal acquaintances as targets. The technique is also important for consumers more broadly because it relies on ordinary account-permission screens that can look legitimate and familiar.
WARNING SIGNS
• An unexpected message from an unfamiliar number or account asking you to open a file, invitation, shared document, or identity-verification link.
• A sender claiming to be a government official, journalist, event organizer, media contact, or other trusted person whom you did not independently verify.
• A Google, Microsoft, or other legitimate-looking permission screen asking an unfamiliar application for broad access to email, files, contacts, or account data.
• Pressure to click Allow, Approve, Continue, or Grant Access before you have verified why the application needs those permissions.
WHAT CONSUMERS SHOULD DO
Do not approve account permissions for an application you do not recognize or did not intentionally initiate. Independently verify the identity of anyone who sends an unexpected file-sharing or account-authorization link. Review the application name and requested permissions carefully before approving access. If you believe you already approved a malicious application, remove or revoke that application’s access in your account security settings; changing your password alone may not remove the malicious authorization token. Preserve screenshots and report suspected incidents to the FBI at IC3.gov or your local FBI field office.
WHY THIS DEVELOPMENT MATTERS
Most consumers are trained to watch for fake login pages and stolen passwords. OAuth consent phishing is different: the login page may be legitimate, and the attacker may never receive the password. The victim is instead tricked into granting the attacker’s application permission to act on the victim’s behalf. That makes careful review of app-permission prompts just as important as password security and multi-factor authentication.
SOURCE ATTRIBUTION
Primary official source: FBI Internet Crime Complaint Center (IC3), Public Service Announcement I-090126-PSA, September 1, 2026 — https://www.ic3.gov/PSA/2026/PSA260901
Report suspected cyber-enabled fraud to IC3 — https://www.ic3.gov
AIGISHIELD ASSESSMENT
This qualifies as an Official Government Warning and a materially important phishing variation because attackers can abuse legitimate OAuth authorization workflows to obtain persistent account access without directly stealing a password.
Think it might be a scam? Let AigiShield check it out for you.
Think Before You Click. Verify Before You Trust.
Comments