ZeroHour
CyberScooppublished ()ingested @CyberScoopNews

FBI raises alarm over deceptive phishing campaign targeting prominent people

mediumPhishing & fraudimportance 62
AI summary · glm-5.3-flash

The FBI warns of an ongoing OAuth consent phishing campaign granting attackers persistent access to high-profile victims' cloud accounts without passwords.

The FBI says attackers impersonate government officials, journalists and event coordinators on commercial messaging apps to trick prominent individuals, their families and acquaintances into authorizing malicious OAuth applications on Microsoft or Google cloud services. Once approved, attackers gain persistent access to emails, files and other sensitive data; the access survives password changes and bypasses MFA, and can only be revoked by invalidating the OAuth token in security settings. The campaign has been tracked since late 2025, and the FBI advises independently verifying senders and granting access only to trusted applications.

  • OAuth consent phishing grants persistent account access without passwords or MFA
  • Actors impersonated government officials, journalists and event coordinators as lures
  • Access persists until the victim invalidates OAuth tokens in app security settings
  • Attackers gain visibility into configured permissions, emails and files
  • FBI has tracked the campaign since late 2025
Full article602 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

The ongoing social engineering threat, which dates back to late 2025, tricks victims into granting threat actors long-term access to their accounts.

Listen to this article

0:00

Learn more.

The headquarters of the Federal Bureau of Investigation on August 16, 2022, in Washington. (Matt McClain/The Washington Post via Getty Images)
The headquarters of the Federal Bureau of Investigation on August 16, 2022, in Washington. (Matt McClain/The Washington Post via Getty Images)

Attackers are targeting prominent, high-profile people, their family members and acquaintances on a commercial messaging application to gain long-term access to their accounts containing sensitive data, the FBI warned in an alert Tuesday.

Officials did not describe the objectives or origins of the attackers, which have more recently impersonated government officials, journalists and publicly known personalities. Attackers are tricking victims into granting them access to a legitimate cloud service, such as Microsoft or Google, under the guise of reviewing a draft article or document.

The ongoing threat, which the FBI has been tracking since late 2025, showcases a “deceptive, sophisticated approach to access user accounts without requiring a password,” the FBI wrote in the public service announcement. The malicious links, which enable OAuth consent phishing, provide attackers with persistent access to a targeted victim’s account.

“Once permission is obtained, it can only be revoked by the victim invalidating the token in their application security settings — not by changing the password,” the FBI wrote.

Authorities did not provide any details about the victims targeted by the campaign or how many people have already been compromised by these attacks. Threat actors previously impersonated event coordinators and planners, using invitations and identity verification requests as lures to gain access to their accounts.

By social engineering unsuspecting victims via OAuth consent phishing, attackers gain full visibility into the target’s configured permissions, allowing them to access emails, files and other sensitive data.

“If the user approves the request, they unwittingly grant high-level access to a malicious application controlled by the cyber actor,” the FBI added. “By registering malicious applications through legitimate authorization protocols and using social engineering tactics, cyber actors can bypass both passwords and multi-factor authentication, which makes consent phishing especially dangerous.”

OAuth is a standardized and widely adopted protocol for authorizing access to applications and other services, including APIs. The standard uses tokens to establish and maintain authorized access to separate resources or services. 

The FBI encouraged people to scrutinize communications from unfamiliar phone numbers or accounts, independently verify the identity of the sender and only grant access to trusted applications.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/fbi-alert-oauth-consent-phishing-campaign/