The U.S. Federal Bureau of Investigation (FBI) has issued an advisory warning of a wave of OAuth consent phishing attacks targeting “prominent victims, their family members, and personal acquaintances.”
OAuth phishing is an increasingly popular social engineering tactic that tricks users into granting access to their accounts without handing over their passwords.
“OAuth consent phishing is a deceptive, sophisticated approach to access user accounts without requiring a password,” the FBI explains. “It typically begins with a phishing email or direct message through a CMA and, when the user clicks the malicious link, they are redirected to a legitimate communication provider permission request screen. If the user approves the request, they unwittingly grant high-level access to a malicious application controlled by the cyber actor. From that moment, the cyber actor can act on behalf of the user, including reading and sending emails, and accessing sensitive data without having access to the user's credentials. By registering malicious applications through legitimate authorization protocols and using social engineering tactics, cyber actors can bypass both passwords and multi-factor authentication, which makes consent phishing especially dangerous.”
The FBI says ongoing attacks are targeting users on messaging apps by impersonating authority figures. “Recently observed activity includes impersonating government officials, media, and other publicly known personalities on a commercial messaging application (CMA) and soliciting the targeted individual to access a malicious link under the guise of a file sharing service through an application under the malicious actor's control,” the FBI says. “Previous phishing campaigns have also impersonated event coordinators and planners, who sent malicious links to targets under the guise of an invitation to an event and the need to verify the target's identity through a malicious application under the actor's control.”
The Bureau notes that users need to be aware of this technique and be on the lookout for requests for access. “Historically, spear phishing efforts focused on social engineering ruses with links or access to malicious credential harvesting sites or malware deployment to gain access to target accounts or devices,” the advisory says. “OAuth consent phishing provides actors with persistent access to a target's account because once permission is obtained, it can only be revoked by the victim invalidating the token in their application security settings; not by changing the password.”
The FBI has the story: https://www.ic3.gov/PSA/2026/PSA260901
