Attackers are going after prominent individuals through OAuth phishing, FBI warns – Help Net Security

Attackers are going after prominent individuals through OAuth phishing, FBI warns – Help Net Security
The FBI warns that attackers are using OAuth consent phishing to target prominent individuals, their relatives, and personal contacts in order to gain persistent access to private emails and files without needing a password. Victims are tricked into approving malicious applications that can bypass passwords and multi-factor authentication, and access must be revoked through account security settings. #FBI #IC3 #OAuth #Microsoft #Google

Keypoints

  • Attackers are targeting prominent individuals and their contacts through OAuth consent phishing.
  • The scam uses social engineering and impersonation on messaging apps and email.
  • Victims are lured to a legitimate login page and asked to approve a malicious app.
  • Once approved, the attacker can access emails, files, and other sensitive data.
  • Password changes do not remove access; the token must be revoked in security settings.

Read More: https://www.helpnetsecurity.com/2026/09/02/oauth-consent-phishing-fbi-warning/