"[A] deceptive, sophisticated approach to access user accounts without requiring a password," the FBI warned, summarizing a phishing campaign it has tracked since late 2025 that aims to secure long‑term access to high‑profile victims' cloud accounts.
How the OAuth consent phishing technique works
The FBI describes a multi-step social engineering play that does not steal passwords but instead convinces targets to grant a malicious application permission to their cloud accounts. Malicious links in messages lead victims through an OAuth consent flow tied to legitimate cloud services — the FBI cites Microsoft and Google as examples — and supply attackers with tokens that maintain authorized access. Those tokens, not passwords, establish and preserve the connection: "Once permission is obtained, it can only be revoked by the victim invalidating the token in their application security settings — not by changing the password," the agency wrote.
Who is being targeted and how they are lured
According to the alert, attackers are focusing on prominent, high‑profile people, their family members and acquaintances, using a commercial messaging application as the initial contact channel. The FBI says the threat actors have impersonated government officials, journalists and publicly known personalities to make requests seem legitimate. Lures reported in the advisory include invitations to review a draft article or document and, in earlier activity, event invitations and identity‑verification requests used by actors posing as event coordinators and planners.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleWhy this approach is especially dangerous, per the FBI
The bureau explains that consent phishing circumvents traditional barriers. "If the user approves the request, they unwittingly grant high‑level access to a malicious application controlled by the cyber actor," the FBI wrote. Attackers register malicious applications through legitimate authorization protocols and pair them with social engineering, which the alert says lets them bypass both passwords and multi‑factor authentication. The FBI highlights that consent phishing gives attackers full visibility into a target’s configured permissions and the ability to access emails, files and other sensitive data.
Guidance the FBI has issued to potential targets
To blunt the tactic, the FBI advises recipients to scrutinize communications that arrive from unfamiliar phone numbers or accounts, to independently verify the sender’s identity, and to grant access only to trusted applications. The advisory draws attention to a behavioral gap: because access is tied to tokens and application permissions, routine practices such as changing a password will not terminate a malicious application’s access — victims must invalidate the token in the application’s security settings to remove it.
What this means for technologists, affected enterprises, and end users
- Technologists and security teams: Expect persistent token‑based access to be the central forensic artifact. Monitor authorized application listings, log and alert on new consent grants, and provide clear, simple workflows for users to review and revoke application tokens.
- Affected enterprises and procurement leaders: Reassess who can grant third‑party permissions and tighten approval processes for external applications. Inventory and centralize visibility into which apps have cloud service access so revocation does not depend solely on end users.
- End users and family members of high‑profile individuals: Treat unexpected requests to "review" drafts or verify identities with caution, verify senders independently, and remember that changing a password will not remove a previously granted application token — revocation must be done in application security settings.
The FBI did not disclose the campaign’s objectives, origins, or how many victims have been affected, leaving the public with a technical warning: tokenized consent can be a durable key in an attacker’s hand. For anyone who receives an unexpected link asking to open or authorize a document, the bureau’s message is plain — verify the sender, verify the application, and if access is granted accidentally, go to your application security settings and invalidate the token.




