We have been told for years to protect our passwords and turn on multi-factor authentication. Good advice that is still valid, but the FBI is warning about a phishing trick that can sometimes sidestep both.
The FBI’s Internet Crime Complaint Center (IC3) recently warned about a growing threat called OAuth consent phishing. The attacks have been targeting prominent individuals, their family members and personal contacts since late 2025, but the technique is worth understanding because it could eventually be used against a much broader audience.
Here’s the sneaky part.
You receive a message that appears to come from someone you know, a journalist, government official, event organizer or another trusted source. The message includes a link to something harmless-sounding, such as a document, invitation, or file-sharing service.
Click the link and you may be taken to a legitimate Google, Microsoft, or other familiar login or authorization page. This is often a feature of other websites or apps these days. You can use your Google, Facebook, Apple, or other credentials to log into a separate one. In this case, nothing looks obviously wrong, so it doesn’t trigger any warning signals. You may then see a request asking you to give an application permission to access your account.
Click Allow, and that’s where the trouble begins.

Instead of stealing your password, the criminals trick you into giving their malicious application permission to access your account. Depending on the permissions granted, that could allow them to read emails, access files, or send messages as you. Even worse, changing your password may not kick them out. You can only get rid of the access by revoking it through your account’s security settings. And that’s what you should do…without hesitation.
Avoiding it is the best strategy
The FBI recommends treating unexpected messages from unfamiliar numbers or accounts with extra suspicion. If someone sends you a link, independently verify that the person actually sent it before clicking. If you’re not expecting it, that’s also a big red flag that needs further investigation.
And perhaps most importantly, don’t use any other credentials for multiple websites. Each site you log into needs its own unique password. Don’t automatically click “Allow” when an application asks for access to your account. Stop and ask yourself whether you recognize the application and whether it really needs the permission it’s requesting. The vast majority of the time, it doesn’t.
The FBI asks that if you believe you have been the victim of this attack, contact your relevant security officials, such as the local police. The also asks that victims report any incident to their local FBI Field Office or the Internet Crime Complaint Center (IC3).