(TLP:CLEAR) FBI Warns of OAuth Consent Phishing Targeting User Accounts
Created: Thursday, September 3, 2026 - 14:22
Categories: Cybersecurity, Federal & State Resources, Security Preparedness
Summary: The FBI has released a public service announcement (PSA) warning that malicious cyber actors are using a technique known as OAuth consent phishing to gain persistent access to victim accounts. OAuth is an authorization framework that lets an application request access to a user’s account on another service without exposing the user’s password. In these campaigns, actors impersonate officials, media, event coordinators, or other known contacts and send a malicious link, often through a commercial messaging application. When the target approves the request, they unknowingly grant the attacker high-level permissions allowing them to read and send emails and access sensitive data. Because the attacker registers the application through legitimate authorization protocols, this method bypasses both passwords and multi-factor authentication (MFA).
Analyst Note: What makes this technique dangerous is its persistence. Once a user grants consent, changing the password does not remove the attacker’s access. The malicious token can only be revoked by invalidating it directly in the account’s application security settings. Mitigations include independently verifying unexpected senders and scrutinizing messages from unfamiliar accounts or numbers. Members can also review connected third-party apps in their email and cloud environments and confirm that staff know how to revoke suspicious tokens.
Original Source: https://www.ic3.gov/PSA/2026/PSA260901
Additional Reading:
Related WaterISAC PIRs: 6, 7, 7.1, 10, 12
