Skip to Content
Join the Network with Us — Join Membership


Your Password May Be Safe, But Hackers Could Still Take Control of Your Account, FBI Warns

September 2, 2026

The FBI has issued a public service announcement warning internet users about a growing phishing technique called OAuth consent phishing, a method cybercriminals are increasingly using to gain access to victims' accounts without ever needing to steal their password directly.

What OAuth Consent Phishing Actually Is

OAuth is a widely used authorisation system that lets websites and apps request access to a user's account without requiring them to hand over login credentials directly, think of it as the mechanism behind "Sign in with Google" or "Connect your account" buttons. Cybercriminals have found a way to abuse this legitimate process, creating fake applications and tricking victims into approving access to them.

According to the FBI, attackers typically start with phishing emails or messages that redirect users to authorisation pages designed to look completely legitimate. If a user approves the request, they unknowingly grant permissions that let criminals access account information, without the attacker ever needing to know the actual password at all.

What makes this particularly concerning compared to traditional phishing: because access is granted through an authorisation token rather than a stolen password, attackers can potentially maintain access indefinitely, right up until the victim manually goes in and removes that permission from their account settings. Simply changing your password wouldn't cut off this kind of access on its own.

How Attackers Are Building Trust

The FBI's cyber division said recent cases have involved attackers impersonating government officials, media organisations, and other public figures to lend credibility to their messages. Criminals have also used fake file-sharing or application-related messages, the kind that look like a routine document-sharing request, specifically to get victims to approve a malicious access request without a second thought.

The agency warned that once granted, this kind of access can let attackers reach emails, documents, and other sensitive information connected to the compromised account. Some campaigns have also involved criminals impersonating known contacts or organisations directly, deliberately manufacturing a false sense of trust to lower a victim's guard before the actual request comes through.

How to Actually Protect Yourself

The FBI's core advice is to be genuinely cautious before approving any account access request, particularly from unfamiliar applications or unexpected messages. Verify who's actually sending the request before doing anything, and avoid granting permissions to services you don't recognise, even if the request itself looks polished and legitimate.

Experts also recommend regularly reviewing the list of connected applications in your account's security settings, most major platforms let you see exactly which third-party apps currently have access, and removing permissions for anything you no longer use or don't recognise. This kind of periodic cleanup closes off access that may have been quietly granted months or years earlier and simply forgotten about.

The FBI emphasised that checking the actual source of unexpected messages, and carefully reading through what an authorisation request is actually asking to access before clicking approve, remains one of the simplest and most effective ways to prevent this kind of unauthorised access from happening in the first place.

FAQs

Q1. What is OAuth consent phishing?

A phishing technique where attackers trick users into approving access for a fake application through the legitimate OAuth authorisation system, gaining account access without ever needing to steal a password.

Q2. How is this different from traditional phishing?

Traditional phishing typically aims to steal passwords directly. OAuth consent phishing instead tricks users into granting permission through an authorisation token, which can give attackers ongoing access even if the password is never compromised.

Q3. How can I check if I've unknowingly granted access to a malicious app?

Regularly review the list of connected or authorised applications in your account's security settings and remove access for anything you don't recognise or no longer use.

Q4. What tactics are attackers using to convince people to approve access?

Impersonating government officials, media organisations, known contacts, or sending fake file-sharing and application-related messages designed to appear legitimate and trustworthy

in News
Share this post
Archive