Skip to main content

Morning Overview

The FBI says a new account takeover works even after you change the password

The FBI’s Internet Crime Complaint Center has issued a public advisory warning that a phishing technique circulating since late 2025 lets criminals keep access to an email or file-sharing account long after the account holder resets their password. The bureau says the method, known as OAuth consent phishing, has targeted prominent public figures along with their family members and personal acquaintances, and it works by exploiting a permission system rather than stealing a login directly.

Traditional phishing tries to capture a username and password. This scheme instead tricks someone into approving a malicious application’s request for ongoing access to their account. Once that request is approved, the attacker never needs the victim’s credentials, and a routine password change does not remove the access that was granted.

How Consent Phishing Sidesteps the Login Screen

OAuth is the authorization framework behind many everyday “sign in with Google” or “connect a Microsoft account” prompts. It lets one application request specific permissions on another service without the user ever handing over a password to the requesting app. That design is meant to make life easier and more secure for ordinary users, since a person never has to type a password into an app they don’t fully trust. The FBI’s advisory explains that malicious actors have learned to turn that convenience against victims by registering their own applications with legitimate providers, then disguising them as something unremarkable, such as a file-sharing tool or an identity-verification service, before sending a target a link.

Because the entire exchange happens through a real provider’s own systems, the warning signs people are usually taught to look for, a misspelled domain, a fake login box, a suspicious pop-up, are largely absent. The login screen a victim sees is the authentic one, hosted by the authentic company, which is part of why the bureau considers the technique unusually effective against otherwise careful users.

Why a Password Reset Doesn’t Close the Door

The advisory’s central warning is about persistence. Once a victim approves the permission request, the resulting access token lives inside the malicious application’s own settings, separate from the account’s password. According to the bureau, that access “can only be revoked by the victim invalidating the token in their application security settings; not by changing the password.” A person who notices something is wrong and resets their password may reasonably believe the problem is solved, when the attacker’s connection has not actually been touched.

The Impersonation Pattern the Advisory Describes

The FBI says recently observed campaigns have involved actors impersonating government officials, members of the media, and other publicly known figures on commercial messaging applications, then contacting a target directly and asking them to open a link framed as a file-sharing request, often posing as a journalist or academic asking the recipient to review a draft article or document. Earlier waves of the same campaign impersonated event coordinators and planners, inviting targets to verify their identity through an application in order to receive details about an invitation. In both patterns, the request is designed to look like an ordinary, low-friction professional ask rather than a suspicious login attempt, and the advisory notes that targeting has extended beyond the prominent individuals themselves to their family members and personal acquaintances, who may have no public profile of their own but still hold access worth stealing.

What Happens After Someone Approves the Request

When a target clicks through, they land on a genuine login page belonging to a real provider, such as a major email or productivity platform, and enter their own credentials there. Those credentials go to the legitimate provider, not to the attacker. The danger comes at the next step, when a pop-up asks the target to grant the application specific permissions. If they approve it, the FBI says the attacker’s application gains visibility into whatever was authorized, which can include reading and sending email or accessing stored files, all without ever possessing the account’s password or a multi-factor authentication code.

The FBI’s Recommended Response

The advisory’s mitigation guidance is aimed at prevention and cleanup rather than technical detection. It urges people to treat messages from unfamiliar phone numbers, accounts, or contacts outside their known circle with added scrutiny, and to independently verify a sender’s identity before acting on a request, rather than relying on the identity a message claims for itself. It also tells people to grant authorization only to applications they actually trust, and, for anyone who suspects they already approved a malicious app, to go into their account’s security or application-permissions settings and revoke access directly, since that step, not a password change, is what actually cuts the connection.

Reporting a Suspected Compromise

Anyone who believes they have been targeted is asked to notify their organization’s security officials where applicable and to file a report with the FBI’s Internet Crime Complaint Center, either through a local FBI field office or the IC3 website. The bureau asks victims to preserve any evidence, including screenshots of the messages that led to the compromise, when they file a report. The advisory does not name specific applications or providers exploited in the campaigns, focusing instead on the mechanism and the behavioral warning signs it wants the public to recognize.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview