Published: · Region: Global · Category: cyber

FBI Warns OAuth Phishing Campaign Is Targeting High‑Profile Americans’ Cloud Accounts

The FBI says a phishing campaign active since late 2025 is tricking prominent people, their families and associates into granting attackers access to their Microsoft and Google accounts via fraudulent OAuth consent requests delivered through consumer messaging apps.

A method many users barely notice when they log into an app has become the centerpiece of a quiet campaign against some of the United States’ most prominent citizens.

The FBI has warned that since late 2025, attackers have been running a phishing operation that targets high‑profile individuals, their family members and close associates by abusing OAuth, the technology used to let one service access another with a click of consent. Instead of stealing passwords, the campaign aims to trick victims into granting long‑lived access tokens to their Microsoft and Google accounts.

According to the bureau’s alert, the attackers pose as officials, journalists or event organizers and reach out over common consumer messaging apps. They send links that appear to come from legitimate services and prompt the recipient to approve an access request—often framed as necessary to view documents, confirm attendance at an event or complete some other routine task. The consent screens themselves connect to real Microsoft and Google infrastructure, which makes the ruse harder to spot.

When a target clicks allow, the attackers receive an OAuth token, a kind of digital key that lets a third‑party application access parts of a user’s account. Unlike classic phishing, which relies on stealing passwords that can be reset or protected with multi‑factor authentication, these tokens can let attackers read emails, browse files, harvest contacts and monitor calendars without ever knowing the login credentials. Because the access is technically authorized by the user, it can blend in with normal account behavior.

For politicians, executives, activists, celebrities and their families, email and cloud storage can contain sensitive correspondence, legal documents, business plans and personal material. Compromise can lead to blackmail, strategic leaks, market manipulation or deep violations of privacy. Associates and staffers may be targeted precisely because their accounts are seen as softer entry points into more heavily guarded inner circles.

Operationally, the campaign shows how attackers are adapting to an environment in which traditional password theft is getting harder. As organizations roll out multi‑factor authentication and better endpoint security, going around the password by exploiting the trust built into OAuth flows becomes more attractive. The use of commercial messaging apps rather than enterprise email to initiate contact further helps attackers bypass corporate filters and depends on individuals’ judgment in informal channels.

From a national security and geopolitical perspective, the profile of the targets matters. While the FBI alert does not publicly attribute the campaign to a specific state or group, the focus on prominent individuals and their networks would make this kind of operation valuable for foreign intelligence services, organized crime or politically motivated actors seeking leverage over public figures.

Key signs to watch in the near term will be whether additional technical details emerge that tie the campaign to known groups, whether Microsoft and Google introduce stronger, more transparent consent controls or warning labels for high‑risk access requests, and whether public figures begin reporting sudden, unexplained access events or leaks that may trace back to this style of token‑based intrusion.

Sources