FBI warns OAuth consent phishing is exposing prominent targets’ Microsoft and Google accounts
The FBI says a phishing campaign is tricking prominent people, their families and associates into granting OAuth access to attackers posing as officials, journalists and event organizers.
The FBI is warning that attackers are using a subtle phishing technique to gain long‑term access to the online accounts of prominent people, their relatives and close associates by exploiting how major tech platforms handle app permissions.
According to the bureau, the campaign has been active since late 2025 and targets high‑profile individuals as well as people around them. Attackers contact victims through common messaging apps while impersonating government officials, journalists or event organizers.
Instead of sending a fake login page, the attackers send links that lead to real permission prompts from services such as Microsoft and Google. These prompts use OAuth, a standard system that lets users grant specific apps access to parts of their accounts—like email, files or calendars—without sharing passwords.
If a victim approves the request, the malicious application receives tokens that allow it to connect to the account through cloud‑service interfaces. Because this access is granted through legitimate mechanisms, it can continue even if the user later changes their password or uses multi‑factor authentication.
The FBI says the result can be deep, long‑lasting compromise: attackers may be able to read and forward emails, copy files, monitor calendars and, in some cases, send messages that appear to come from the victim. Since no obvious account takeover occurs, victims may not notice that an unauthorized app now has access.
For political figures, business leaders, journalists and celebrities, this can expose sensitive communications and documents. Family members or assistants can become indirect entry points into the accounts of more prominent targets.
The alert illustrates a broader shift in hacking tactics toward abusing cloud‑based identity and access systems: instead of breaking passwords, attackers focus on persuading users to grant them legitimate‑looking permissions.
Indicators to watch include whether the FBI or technology companies attribute the campaign to specific groups, and whether providers such as Microsoft and Google change default OAuth settings or add stronger warnings around high‑risk permission requests. Reports of high‑profile account compromises linked to this technique would suggest that the campaign is reaching especially sensitive targets.
Sources
- OSINT