The FBI warned that attackers are using OAuth consent phishing on a commercial messaging app to target high-profile people, their families, and acquaintances, tricking them into granting access to legitimate cloud services like Microsoft or Google. Once approved, the malicious app can maintain persistent access to emails, files, and other sensitive data even if the victim changes their password. #FBI #Microsoft #Google #OAuth
Keypoints
- Attackers are targeting prominent people and their close contacts through a commercial messaging application.
- They impersonate officials, journalists, and public figures to gain trust.
- Victims are lured into approving malicious access to Microsoft or Google accounts.
- OAuth consent phishing can bypass passwords and multi-factor authentication.
- The FBI advises verifying senders and only approving trusted applications.
Read More: https://cyberscoop.com/fbi-alert-oauth-consent-phishing-campaign/