The FBI warned of an ongoing targeted OAuth consent-phishing campaign in which attackers impersonate government officials, media figures, public personalities, event organizers, and other trusted contacts through phishing emails and commercial messaging applications. The activity, observed since late 2025, targets prominent individuals as well as their relatives and acquaintances, luring them into authorizing attacker-controlled applications.
Granting consent gives attackers persistent, high-level access to cloud accounts, including email and sensitive data, through legitimate OAuth authorization flows rather than stolen passwords. The access can survive password changes and bypass conventional password and multifactor authentication protections until the victim explicitly revokes the malicious application's permissions in account security settings. The FBI advised users to verify unsolicited contacts, authorize only trusted applications, and closely review requested OAuth permissions.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
The FBI issued a warning about the ongoing campaign, in which phishing emails or commercial messaging-app messages lure targets into approving attacker-controlled applications. The resulting OAuth tokens can provide persistent access to email and sensitive cloud data without obtaining passwords or directly defeating MFA.
The FBI observed malicious actors conducting targeted OAuth consent-phishing attacks against prominent individuals, their relatives, and acquaintances since late 2025. The actors impersonated trusted public figures and used malicious OAuth applications to obtain authorized cloud-account access.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.