# FBI Warns OAuth Consent Phishing Campaign Is Targeting High‑Profile Cloud Accounts

*Wednesday, September 2, 2026 at 6:19 AM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-09-02T06:19:50.145Z (1h ago)
**Category**: cyber | **Region**: Global
**Importance**: 7/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/16589.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: The FBI says attackers have, since late 2025, used OAuth consent prompts in Microsoft and Google apps to gain quiet access to prominent people’s accounts, including those of their families and associates.

The FBI is warning that a phishing campaign is exploiting a common cloud‑security feature to target prominent individuals and those close to them.

According to the bureau, the campaign has been active since late 2025 and has focused on prominent people, their family members and associates. Attackers pose as officials, journalists or event organizers and contact targets via commercial messaging apps, attempting to persuade them to click links that ask for “OAuth consent” to access their Microsoft or Google accounts.

OAuth is an authorization standard that allows users to grant applications access to parts of their accounts—such as email, files or contacts—without sharing a password. In this campaign, the FBI says attackers are abusing that trust by getting victims to approve access for what appear to be legitimate Microsoft and Google applications.

Once a victim grants consent, the attacker obtains a token that lets them use the account within the permissions allowed, often including email, cloud storage and contact lists. Because no password is stolen or guessed, usual warning signs such as unfamiliar login alerts may not appear, making the intrusion harder to spot.

For high‑profile targets, this method offers attackers a way into sensitive correspondence at the center of politics, business or public life, not only through the individuals themselves but also through people around them who might have weaker defenses but access to useful information.

From a defensive perspective, the campaign shows how attackers can operate entirely within mainstream cloud platforms and standard login flows, blending their activity into normal traffic. That raises the stakes for how people handle app permission prompts and how cloud providers help users understand what they are approving.

Key developments to watch will be whether the FBI or partner agencies link this activity to a specific state or criminal group, whether Microsoft and Google change how they present OAuth consent for higher‑risk users, and whether any public breaches are traced back to the kind of token misuse described in the warning.
