As cited
Copy frozen at (site build).
threat intel
Attackers are going after prominent individuals through OAuth phishing, FBI warns
The Federal Bureau of Investigation (FBI) has warned that attackers are targeting prominent individuals and their contacts using OAuth consent phishing attacks to gain persistent access to accounts including private emails and files. The technique, which has been active since late 2025, exploits the OAuth framework to deceive users into granting access without requiring passwords. The FBI's Internet Crime Complaint Center (IC3) characterizes the approach as sophisticated and deceptive.
Why it matters: High-profile individuals and their personal networks face account compromise and data theft through a technique that bypasses password requirements; practitioners should review OAuth consent flows and train users to verify application permissions before granting access.
- Source published
- First seen by Cybersecurity Tracker