The FBI has issued a public service announcement warning internet users about a growing phishing technique known as OAuth consent phishing, which cybercriminals are using to gain access to victims’ accounts without stealing their passwords directly.
The FBI’s cyber division said malicious actors are targeting individuals, family members and personal contacts by sending deceptive messages designed to trick users into granting access to harmful applications.
What is OAuth consent phishing and how does it work?
OAuth is a commonly used authorization system that allows websites and applications to request access to a user’s account without requiring the user to share login credentials. However, cybercriminals are abusing this process by creating fake applications and convincing victims to approve access.
According to the FBI, attackers often begin with phishing emails or messages that redirect users to legitimate-looking authorization pages. If users approve the request, they unknowingly provide permissions that allow criminals to access account information.
Unlike traditional phishing methods that focus on stealing passwords, OAuth consent phishing can allow attackers to maintain access through authorization tokens until the permission is removed from account settings.
Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions
Cybercriminals using fake identities to target victims
The FBI said recent cases involved attackers impersonating government officials, media organizations and other public figures. Criminals have also used fake file-sharing or application-related messages to convince users to approve malicious access requests.
The agency warned that attackers may use these techniques to access emails, documents and other sensitive information connected to compromised accounts.
Some phishing campaigns have also involved criminals pretending to be known contacts or organizations, creating a false sense of trust among victims.
How internet users can stay protected
The FBI advised users to be cautious before approving account access requests from unfamiliar applications or messages. Users should verify the identity of the sender and avoid granting permissions to unknown services.
Experts recommend regularly reviewing connected applications in account security settings and removing access for applications that are no longer required.
The FBI emphasized that checking the source of unexpected messages and carefully reviewing authorization requests can help prevent criminals from gaining unauthorized access to online accounts.
About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.