FBI Warns OAuth Phishing Campaign Targeting Prominent Figures Exposes Email and Cloud Data at Scale
The FBI says attackers have spent months impersonating officials, journalists and event organizers to trick high‑profile targets into granting OAuth access to their Microsoft and Google accounts. The scheme hands over cloud‑level control without stealing passwords, putting inboxes and documents of politicians, executives and their families at risk.
A long‑running phishing campaign aimed at prominent people in the United States and abroad is exploiting a less visible but highly powerful gateway into victims’ digital lives: OAuth consent to cloud accounts instead of stolen passwords.
In a recent alert, the FBI said the campaign has been active since late 2025, targeting high‑profile individuals, their relatives and close associates. Rather than relying on traditional email scams, attackers have been using commercial messaging apps and personalized outreach, posing as government officials, journalists or event organizers to gain trust.
The hook is not a malicious attachment or a request for login credentials. Instead, targets are directed to what appear to be legitimate Microsoft or Google pages, where they are asked to grant an application access to their email or cloud storage via OAuth, the standard protocol that lets users authorize one service to interact with another without sharing their passwords.
Once a victim clicks “consent,” the attackers receive long‑lived access tokens that allow them to read emails, download files and in some cases send messages as the victim—all without ever learning or changing the account’s password. Because the access is technically authorized, it can be harder for both users and some security tools to distinguish from normal activity.
The FBI warning did not name specific individuals or organizations hit by the campaign, but by stressing that “prominent individuals” and their circles are being targeted, it suggests a mix of political, business, media and possibly entertainment figures. For such people, the value of a compromised inbox goes well beyond personal privacy: it can expose negotiations, legal strategies, financial movements and sensitive contacts. The inclusion of family members and associates broadens the attack surface further, offering adversaries a way in even if a primary target has strong personal security habits.
Operationally, OAuth‑based attacks reflect how threat actors are adapting to an environment in which multi‑factor authentication, password managers and user education have made simple credential theft less reliable. By attacking the trust model of modern cloud ecosystems, they can achieve durable access that persists even if a user later changes their password. For defenders, the challenge is to monitor not just logins but the web of third‑party app permissions attached to high‑value accounts.
Strategically, a successful campaign against prominent figures’ cloud accounts can pay off in espionage, influence operations or financial crime. Stolen emails and documents can be leaked selectively to sway public debates, extortion can be used to shape decisions, and access to calendars and private messages can help adversaries map networks of influence. Because many officials and executives continue to use personal accounts alongside official ones, the boundary between private and institutional risk is porous.
The warning also illustrates how the most impactful cyber operations often do not rely on zero‑day software exploits but on convincing humans to approve something they only half understand. A single misplaced click can give away years of correspondence and sensitive files, even if every device in the chain is technically up to date and patched.
Key indicators to watch will be whether additional government agencies or technology companies supplement the FBI’s alert with their own data, whether any major public figures disclose being affected, and if cloud providers move to tighten default OAuth permissions for high‑risk accounts. Any publicized leak or disruption traced back to this campaign would turn what is now a technical bulletin into a headline‑driving political or corporate crisis.
Sources
- OSINT