FBI Flags OAuth Phishing Against High-Profile Accounts
The FBI warned Tuesday about an ongoing consent-phishing campaign that has targeted prominent people, their family members, and acquaintances since late 2025. Attackers use commercial messaging apps and impersonation of trusted contacts, journalists, or officials to lure victims into approving access to Microsoft or Google accounts.
The trick is a real OAuth approval screen: if the target grants the request, the malicious app gets a standing token that can read mail and files and keep working even after a password change. The FBI said the grant must be revoked in the account’s application security settings; a reset alone does not remove it.
For teams protecting executives, assistants, and public-facing staff, the exposure is the permission grant itself and the contact network around it. A compromise of one trusted account can become a pivot into other linked inboxes and shared information flows until the app authorization is removed.