By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Threatwire
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
      • Drinkware
      • T-Shirts
    • Cart
Reading: FBI flags OAuth consent phishing that survives password resets
0

No products in the cart.

  • AI
  • Android
  • Authentication
  • Breaches
  • CASB
  • Compliance
  • Cryptography
  • Cyberinsurance
  • EDR
  • IAM
  • Malware
  • Phishing
  • Quantum
  • Ransomware
  • SecOps
  • SIEM
  • SOC
  • Threat Intelligence
  • Vulnerabilities
  • Zero Trust
ThreatwireThreatwire
Font ResizerAa
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
  • Newsletter
  • Shop
Search
  • Home
  • News & Alerts
  • Articles
  • Features
  • Spotlight
  • About
    • Mission
    • Services
    • Contact
  • Newsletter
  • Shop
    • All Items
    • By Category
    • Cart
Follow US
  • About Threatwire
  • Services
  • Contact
  • Privacy
  • Legal
©2026 CybersecurityBeat. All Rights Reserved.
News & Alerts

FBI flags OAuth consent phishing that survives password resets

The FBI warns OAuth consent phishing has been seizing prominent people's accounts since late 2025, and password resets do not stop it.

CSBadmin
Last updated: September 3, 2026 6:32 am
CSBadmin
2 Min Read
Share
SHARE

A campaign that began in late 2025 is still prying open the accounts of public figures, their families, and their inner circles, according to a new FBI advisory. The technique, known as OAuth consent phishing, needs no stolen password and slips past multi-factor prompts entirely.

The Internet Crime Complaint Center describes impersonators posing as government officials, journalists, academics, or event organizers on commercial messaging applications. Targets are steered toward a malicious application registered with a legitimate OAuth provider, often named to resemble a file-sharing or identity verification service.

Clicking the link opens a real sign-in screen at the victim’s own provider, which is what makes the ruse convincing. Granting the requested permissions is the point of no return: the app the attacker controls can then page through inboxes and files, and even send mail under the victim’s name. Nothing about the password matters at that stage. The FBI stresses that rotating credentials leaves the attacker untouched, and only removing the app token through account security settings closes the door.

The bureau advises treating messages from unfamiliar numbers with suspicion, verifying a sender’s identity independently, and granting authorization only to trusted applications. It did not attribute the campaign or identify victims.

CSBadmin

The latest in cybersecurity news and updates.

TAGGED:Account Takeoverconsent phishingFBIMFAOAuthPhishing
SOURCES:Help Net SecurityCyberScoop
Share This Article
Facebook Print
ByCSBadmin
Follow:
The latest in cybersecurity news and updates.
Previous Article Iran-linked job scam bans AI help that could flag its hidden RAT
Next Article Two GeoNetwork bugs chain into unauthenticated server takeover

Trending

StreamRat trojan rides fake TV apps to take over Android devices
September 3, 2026
Signed node.exe is latest cover for malware delivery, Symantec finds
September 3, 2026
Russian man extradited over Excel malware sent to 80,000 freelancers
September 3, 2026
Fake tax and shipping lures push RMM installs across 46 countries
September 3, 2026
Poisoned Git configs make AI coding agents run attacker commands
September 3, 2026

Related Stories

CSBadmin

Persistent Backdoor Compromises Cisco Firepower Appliances at a Federal Agency

CSBadmin

Massive Phishing Wave Uses Fake Code of Conduct Scare to Steal Credentials

CSBadmin

Adobe Acrobat browser extension flaw exposed WhatsApp chats on 329 million devices

CSBadmin

Mythos AI Reveals macOS Kernel Bugs That Break Apple’s Memory Defenses

logo-twfull
  • About Threatwire
  • Services
  • Contact
  • Privacy
  • Legal

© 2026 Threatwire / Cybersecurity Beat. All rights reserved.