Alert Number: I-090126-PSA |

Malicious Cyber Actors Gain Access to Victim Accounts Through Consent Phishing


Since late 2025, malicious cyber actors have been targeting prominent victims, their family members, and personal acquaintances by directly messaging personal accounts with malicious links leveraging a technique known as "OAuth consent phishing."

Threat Landscape

Recently observed activity includes impersonating government officials, media, and other publicly known personalities on a commercial messaging application (CMA) and soliciting the targeted individual to access a malicious link under the guise of a file sharing service through an application under the malicious actor's control. Previous phishing campaigns have also impersonated event coordinators and planners, who sent malicious links to targets under the guise of an invitation to an event and the need to verify the target's identity through a malicious application under the actor's control.

How OAuth Consent Phishing Works

Historically, spear phishing efforts focused on social engineering ruses with links or access to malicious credential harvesting sites or malware deployment to gain access to target accounts or devices. OAuth consent phishing provides actors with persistent access to a target's account because once permission is obtained, it can only be revoked by the victim invalidating the token in their application security settings; not by changing the password.

OAuth consent phishing is a deceptive, sophisticated approach to access user accounts without requiring a password. It typically begins with a phishing email or direct message through a CMA and, when the user clicks the malicious link, they are redirected to a legitimate communication provider permission request screen. If the user approves the request, they unwittingly grant high-level access to a malicious application controlled by the cyber actor. From that moment, the cyber actor can act on behalf of the user, including reading and sending emails, and accessing sensitive data without having access to the user's credentials. By registering malicious applications through legitimate authorization protocols and using social engineering tactics, cyber actors can bypass both passwords and multi-factor authentication, which makes consent phishing especially dangerous.

A flowchart titled OAuth Consent Phishing Activities; each step is categorized into Actor or Victim Activities. Step 1: Actor Activity - Create Application; Actor creates a malicious application and registers it with a legitimate OAuth provider. The malicious application may be named to look like something legitimate, such as a third-party personal storage or identity verification service. Step 2: Actor Activity - Actor Sets Permissions; Actor configures the application to have significant permissions, including the ability to read and write files, emails, and more. Step 3: Actor Activity - Send to Victims; Actor sends a phishing email or text message to the target, initiating the consent process for the application. Step 4: Victim Activity - Email or Text Received with URL; Actor initiates social engineering and communicates with the victim, usually impersonating a journalist, academic, etc. with a request to review a draft article or document. Step 5: Victim Activity - Victim Authenticates; Victim is presented with a legitimate cloud service login page, such as Microsoft or Google, and is asked to authenticate with their credentials. (The credentials are not passed to the actor's third-party application.) Step 6: Victim Activities - Victim Grants Permissions for Consent Request; Actor's application will push a pop-up window asking the victim to grant permissions. If they click 'Allow', the actor will have full visibility to configured permissions. This could allow the actor's app to read emails, access files, etc. Because the provider is legitimate, users trust it. Step 7a: Actor Activity - Actor Data Access; If [the Victim clicks] 'Allow', the actor will have full visibility to configured permissions and obtain access to the file stores. This is persistent API access to the user's data without needing a password or MFA. Step 7b: Victim Activity - Token for the App on the Victim's Device; Victim is unaware or may consider the matter remediated with a password change, but this is not the case, as the token ensures persistence despite password changes. Immediate removal of the app via the user's security settings is necessary for remediation.

Tips to Protect Yourself

Mitigation strategies include increased scrutiny of communications from unfamiliar phone numbers, accounts, or that are not part of a known contact list. Additionally, independently verify the identity of the sender and only grant authorization to trusted applications.

Report It

If you believe you have been the victim of the phishing campaign described above, contact your relevant security officials. The FBI requests victims also report any incident to their local FBI Field Office or the Internet Crime Complaint Center (IC3) at http://www.ic3.gov. Report information elicited and maintain screenshots of messages.