CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

FBI Raises Alarm About OAuth Consent Phishing Activity

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6901

As cited

Copy frozen at (site build).

threat intel

FBI Raises Alarm About OAuth Consent Phishing Activity

The FBI warned of ongoing OAuth consent phishing attacks since late 2025 that trick victims into authorizing malicious applications through legitimate OAuth providers like Microsoft 365 and Google. The technique bypasses multifactor authentication (MFA) and persists even after password changes, since the attacker retains the OAuth token granting previously consented permissions. Attackers impersonate high-profile individuals via commercial messaging apps to lure targets into granting excessive permissions such as email access and contact reading.

Why it matters: Any user with cloud service accounts is at risk; OAuth consent phishing grants attackers persistent access without requiring password disclosure or MFA, and revocation requires manual removal of the malicious app from security settings.

VendorsMicrosoftGoogle
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary