VYPR
advisoryPublished Sep 1, 2026· 1 source

FBI Warns of Sophisticated OAuth Consent Phishing Campaign Targeting Prominent Individuals

The FBI has issued an alert regarding a sophisticated phishing campaign targeting prominent individuals using OAuth consent phishing via messaging apps to trick victims into granting persistent access to cloud services.

The FBI has issued a public service announcement warning of a sophisticated phishing campaign that is targeting prominent individuals, their families, and acquaintances. The attackers are employing a deceptive tactic that leverages OAuth consent phishing, primarily through commercial messaging applications, to trick victims into granting unauthorized access to their cloud-based accounts.

This campaign, which the FBI has been tracking since late 2025, bypasses traditional security measures like passwords and multi-factor authentication (MFA). Instead of requesting credentials directly, the threat actors impersonate various figures, including government officials, journalists, and public personalities, to lure victims into approving malicious application requests. These requests often appear benign, such as asking a victim to review a draft article or document.

Once a victim grants consent, the attackers gain persistent access to sensitive data stored within cloud services like Microsoft or Google. This access is particularly dangerous because it cannot be revoked simply by changing the account password. The FBI noted that revoking this access requires the victim to manually invalidate the token in their application security settings, a step many users may not know how to perform or even realize is necessary.

Previous iterations of this campaign saw threat actors impersonating event coordinators and planners, using invitations and identity verification requests as lures. By successfully employing social engineering tactics through OAuth consent phishing, attackers achieve full visibility into the target's configured permissions. This allows them to access emails, files, and other highly sensitive information stored within the compromised accounts.

The FBI emphasized that by registering malicious applications through legitimate authorization protocols and combining this with social engineering, cyber actors can effectively circumvent both passwords and MFA. This makes consent phishing a particularly potent threat, as it exploits a fundamental trust mechanism within modern cloud services.

While the FBI did not disclose the specific objectives or origins of the attackers, nor the number of individuals compromised, the alert serves as a critical warning about the evolving nature of phishing attacks. The agency urged individuals to scrutinize communications from unfamiliar sources, independently verify the identity of senders, and exercise extreme caution when granting access to applications, even when the request appears to come from a trusted source or context.

To mitigate this threat, users are advised to regularly review the applications and services that have been granted access to their accounts and to revoke permissions for any suspicious or unnecessary applications. Staying informed about these evolving threats and practicing vigilant security hygiene are crucial for protecting sensitive personal and professional data from such sophisticated attacks.

Synthesized by Vypr AI