As cited
Copy frozen at (site build).
threat intel
FBI Raises Alarm About OAuth Consent Phishing Activity
The FBI warned of ongoing OAuth consent phishing attacks since late 2025 that trick victims into authorizing malicious applications through legitimate OAuth providers like Microsoft 365 and Google. The technique bypasses multifactor authentication (MFA) and persists even after password changes, since the attacker retains the OAuth token granting previously consented permissions. Attackers impersonate high-profile individuals via commercial messaging apps to lure targets into granting excessive permissions such as email access and contact reading.
Why it matters: Any user with cloud service accounts is at risk; OAuth consent phishing grants attackers persistent access without requiring password disclosure or MFA, and revocation requires manual removal of the malicious app from security settings.
- Source published
- First seen by Cybersecurity Tracker