A campaign that began in late 2025 is still prying open the accounts of public figures, their families, and their inner circles, according to a new FBI advisory. The technique, known as OAuth consent phishing, needs no stolen password and slips past multi-factor prompts entirely.
The Internet Crime Complaint Center describes impersonators posing as government officials, journalists, academics, or event organizers on commercial messaging applications. Targets are steered toward a malicious application registered with a legitimate OAuth provider, often named to resemble a file-sharing or identity verification service.
Clicking the link opens a real sign-in screen at the victim’s own provider, which is what makes the ruse convincing. Granting the requested permissions is the point of no return: the app the attacker controls can then page through inboxes and files, and even send mail under the victim’s name. Nothing about the password matters at that stage. The FBI stresses that rotating credentials leaves the attacker untouched, and only removing the app token through account security settings closes the door.
The bureau advises treating messages from unfamiliar numbers with suspicion, verifying a sender’s identity independently, and granting authorization only to trusted applications. It did not attribute the campaign or identify victims.
