CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Attackers are going after prominent individuals through OAuth phishing, FBI warns

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5547

As cited

Copy frozen at (site build).

threat intel

Attackers are going after prominent individuals through OAuth phishing, FBI warns

The Federal Bureau of Investigation (FBI) has warned that attackers are targeting prominent individuals and their contacts using OAuth consent phishing attacks to gain persistent access to accounts including private emails and files. The technique, which has been active since late 2025, exploits the OAuth framework to deceive users into granting access without requiring passwords. The FBI's Internet Crime Complaint Center (IC3) characterizes the approach as sophisticated and deceptive.

Why it matters: High-profile individuals and their personal networks face account compromise and data theft through a technique that bypasses password requirements; practitioners should review OAuth consent flows and train users to verify application permissions before granting access.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary