ZeroHour

Search: “consent”

370 stories

FBI raises alarm over deceptive phishing campaign targeting prominent people

The FBI warns of an ongoing OAuth consent phishing campaign granting attackers persistent access to high-profile victims' cloud accounts without passwords.

The FBI says attackers impersonate government officials, journalists and event coordinators on commercial messaging apps to trick prominent individuals, their families and acquaintances into authorizing malicious OAuth applications on Microsoft or Google cloud services. Once approved, attackers gain persistent access to emails, files and other sensitive data; the access survives password changes and bypasses MFA, and can only be revoked by invalidating the OAuth token in security settings. The campaign has been tracked since late 2025, and the FBI advises independently verifying senders and granting access only to trusted applications.

CyberScoop · 15d agoPhishing & fraud

Attackers are going after prominent individuals through OAuth phishing, FBI warns

FBI IC3 warns of ongoing OAuth consent phishing since late 2025 targeting prominent individuals to gain persistent, password-free account access.

Attackers register malicious applications with legitimate OAuth providers, impersonate journalists, academics, event organizers, or government officials on messaging apps and email, and lure targets into approving permission requests on real Microsoft or Google login pages. Once approved, the attacker's application can read and send emails and access sensitive files within granted permissions, bypassing both passwords and MFA. The FBI notes password changes do not revoke this access; victims must invalidate the OAuth token in application security settings, and no attribution or victim list has been disclosed.

Help Net Security · 15d agoPhishing & fraud in the wild