WASHINGTON — The FBI is warning that malicious cyber actors have been targeting prominent individuals, their family members, and personal acquaintances through a phishing technique designed to gain persistent access to online accounts without directly stealing passwords.
The technique, known as OAuth consent phishing, has been observed in activity dating back to late 2025, according to FBI Public Service Announcement I-090126-PSA. Attackers send malicious links directly to personal accounts and attempt to persuade targets to approve access for an application controlled by the threat actor.
OAuth is a widely used authorization framework that allows one application or website to request access to information held by another service without requiring the user to disclose their login credentials to the requesting application. The FBI warns that attackers are abusing that legitimate process rather than defeating it directly.
Recent activity observed by the FBI has included threat actors impersonating government officials, members of the media, and other publicly known personalities through a commercial messaging application. Targets were then directed toward malicious links presented as file-sharing services controlled by the attackers.
Previous campaigns used similar social engineering techniques while impersonating event coordinators and planners. In those cases, victims received links presented as event invitations and were told they needed to verify their identities through an application operated by the malicious actor.
The attack differs from conventional credential phishing.
Traditional spear-phishing campaigns often rely on social-engineering links to credential-harvesting sites or malware designed to gain access to accounts or devices. OAuth consent phishing instead attempts to convince the victim to authorize a malicious application through a legitimate service provider.
Once permission is granted, the attacker can obtain persistent access through an OAuth token. According to the FBI, changing the victim’s password does not necessarily remove that access. The token must be invalidated through the application’s security settings to revoke the malicious authorization.
That persistence is one of the central risks associated with the technique.
A victim may believe the account has been secured after changing a password, while an attacker-controlled application can retain authorized access through the previously issued token.
The FBI said a typical attack begins with a phishing email or direct message containing a malicious link. When the target follows the link, the victim may be redirected to a legitimate communication or cloud-service provider’s permission screen.
If the user approves the request, the malicious application can receive the permissions selected by the attacker.
Those permissions can potentially allow the threat actor to read email, send messages, access files, retrieve sensitive information, and act on behalf of the compromised user without obtaining the victim’s password.
The FBI also warned that the technique can defeat assumptions surrounding multi-factor authentication.
Because the victim authenticates directly with the legitimate service and then authorizes the malicious application, the attacker may not need to steal either the password or the second authentication factor. The FBI said this allows consent-phishing operations to bypass both passwords and multi-factor authentication through abuse of legitimate authorization workflows.
The FBI’s illustrated workflow shows the attack beginning with the threat actor creating an application and registering it with a legitimate OAuth provider.
The malicious application may be designed to resemble a normal service, including third-party storage, identity verification, or document-sharing tools.
The attacker then configures the application to request significant permissions, including the ability to read or modify email, files, or other account information.
A phishing message is sent to the target, who is directed to a legitimate cloud-service login page and asked to authenticate with existing credentials.
At that point, the credentials remain with the legitimate provider. The threat actor does not necessarily receive them.
The crucial stage occurs when the victim is presented with a consent window asking whether the application should be granted access.
If the user selects Allow, the malicious application receives an OAuth token corresponding to the permissions that were approved.
The FBI’s diagram explains that this can provide persistent API-level access to the victim’s information without requiring a password or multi-factor authentication code. The token can remain effective until the malicious application’s authorization is explicitly revoked.
The technique is particularly dangerous when high-value targets are involved.
Prominent individuals, their family members, and personal acquaintances may have access to sensitive correspondence, internal documents, contact networks, travel information, business material, or private communications.
Compromising one person can also expose additional information associated with the victim’s account. Depending on the permissions granted, a malicious application may be able to read and send email, access files, and retrieve sensitive account data.
The FBI’s alert stresses that the social engineering component is central to the attack.
The attacker does not necessarily need to exploit a software vulnerability. The objective is to persuade the victim to authorize access voluntarily through a legitimate interface.
That makes the legitimacy of the login page itself an unreliable indicator of safety.
A target may authenticate through a genuine cloud provider and still compromise the account if the application requesting permission is controlled by a malicious actor.
The FBI recommends that users apply greater scrutiny to messages coming from unfamiliar telephone numbers, accounts, or individuals outside established contact lists.
Users should also independently verify the identity of the sender before responding to sensitive requests and should grant authorization only to applications they know and trust.
For individuals who suspect they have already approved a malicious application, changing the password alone may not be enough.
The affected OAuth token or application permission must be revoked through the relevant account-security or application-management settings.
The FBI is asking victims of suspected OAuth consent phishing to notify their appropriate security personnel and report incidents to either their local FBI field office or the Internet Crime Complaint Center, commonly known as IC3.
Victims are also encouraged to preserve screenshots of suspicious messages and retain information provided during the interaction for reporting to the FBI and appropriate security personnel.
The FBI’s warning does not identify a specific threat group responsible for the observed activity and does not attribute the campaign to a particular nation-state or criminal organization.
The alert instead focuses on the technique itself and the growing use of legitimate authorization systems as a route around traditional credential defenses.
The broader security lesson is direct: a valid login page does not guarantee that the application requesting access is trustworthy.
OAuth consent screens can grant extensive permissions to third-party applications, and users should treat requests for access to email, files, account data, or other sensitive information with the same caution applied to password prompts.
Federal Bureau of Investigation — Public Service Announcement I-090126-PSA, “Malicious Cyber Actors Gain Access to Victim Accounts Through Consent Phishing,” dated September 1, 2026. The FBI alert details the OAuth consent-phishing technique, observed targeting patterns, persistence through malicious authorization tokens, and recommended mitigation and reporting steps.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



