# FBI Warns OAuth ‘Consent’ Phishing Campaign Is Targeting High‑Profile Cloud Accounts

*Wednesday, September 2, 2026 at 6:12 AM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-09-02T06:12:01.876Z (1h ago)
**Category**: cyber | **Region**: Global
**Importance**: 8/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/16562.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: The FBI says attackers have been using consent‑based phishing since late 2025 to trick prominent people, their relatives and associates into granting OAuth access to legitimate Microsoft and Google apps, yielding tokens that can silently expose email, files and contacts.

The FBI has warned that a phishing campaign active since late 2025 is going after prominent individuals and people close to them by exploiting the way major cloud services handle access permissions, rather than by stealing passwords.

According to the bureau, attackers have been impersonating officials, journalists and event organizers on commercial messaging apps to contact targets. Instead of directing victims to fake login pages, the messages contain links that lead to real Microsoft and Google authorization prompts asking for OAuth consent.

OAuth is a standard that lets users grant an application access to parts of their account without sharing their password — for example, allowing a third‑party app to read email or manage calendars. In the campaign described by the FBI, targets are asked to approve access for applications that appear legitimate but are controlled or abused by the attackers.

When a victim agrees, the cloud service issues an access token that can allow the requesting app to read or change data such as email, files and contacts, depending on the permissions granted. Because this process uses genuine Microsoft or Google infrastructure, it can bypass traditional phishing protections that focus on spotting fake websites or credential theft. The FBI notes that these access tokens may continue to work even if a user later changes their password.

The advisory says the campaign is aimed at prominent people, their families and their associates. By targeting relatives or close aides rather than the primary public figure, attackers may be able to reach sensitive information such as schedules, correspondence or documents that are shared through cloud accounts.

These attacks can be difficult for users to recognize. Messages may arrive over familiar messaging apps and refer to real‑world events, while the links lead to trusted domains. The main warning sign is often the scope of the permissions requested by the app, which many people may approve quickly without close review.

The FBI has not publicly attributed the activity to a specific group or government. Its warning underscores a broader trend in which intruders focus on manipulating trusted authentication processes in cloud platforms, rather than trying to break into systems directly.

Developments to watch include whether major cloud providers change how they present and control OAuth permissions, and whether any high‑profile breaches are later linked to this type of consent phishing. The effectiveness of such attacks will depend heavily on how carefully users — and especially those around prominent figures — scrutinize the access they grant to apps connected to their accounts.
