The last step of the attack the FBI described on September 1 is a permission prompt drawn by a legitimate cloud provider, and approving it gives a stranger lasting access to a victim’s email and files. The Bureau’s Internet Crime Complaint Center issued the warning as public service announcement PSA260901. Its central sentence is about what cannot fix the damage: once permission is obtained, it can only be revoked by the victim invalidating the token in their application security settings, not by changing the password.
Multi-factor authentication does not help either, because the attacker never needs to log in.
Malicious apps registered with real OAuth providers
In the FBI’s description, the actor builds an application, registers it with a legitimate OAuth provider, and requests significant permissions. A phishing message then goes out by email or a commercial messaging app, impersonating an official or other public figure. The link leads victims to the provider’s genuine sign-in page, and after they authenticate, the provider’s own permission pop-up asks whether to let the application in. Because every screen belongs to the real provider, there is no spoofed domain for a victim to spot. Approval hands the attacker persistent, token-based access through the provider’s API to the victim’s files and email, which in the AHA’s summary of the alert includes reading and sending messages as the victim.
Targets are chosen, not sprayed. Help Net Security reported that the activity is aimed at prominent individuals, their relatives and personal contacts, with senders posing as journalists, academics or government officials, and that the IC3 has tracked it since late 2025. The Bureau has not said who is behind it or named any victims, and the warning offers no estimate of how many accounts have been taken over.
Token-based access that sidesteps passwords and MFA
OAuth exists so that one service can act for a user at another without ever seeing the user’s password. The framework in RFC 6749 has the resource owner grant authorization, which the application exchanges for tokens, and refresh tokens, where issued, are credentials for obtaining new access tokens. A password never enters that exchange after the grant, so changing it removes nothing from the application’s side of the arrangement. The specification describes access tokens as representing specific scopes and durations of access, which makes the breadth of the permissions requested on that one screen the real measure of the damage: a narrow grant exposes little, while the significant permissions the FBI says these apps ask for expose mailboxes and file stores.
Microsoft’s guidance on illicit consent grants arrives at the same conclusion from the defender’s side. Attackers register an app, trick users into consenting through phishing, and gain account-level data access, and Microsoft says password resets and MFA enforcement are ineffective against this class of attack because the app sits outside the organization. The FBI’s advisory says the same of the access it gives: persistent, API-level reach to files and email, with no password to rotate and no MFA challenge to answer.
Revoking the grant in security settings
The FBI’s recommendations are brief: scrutinize messages from unfamiliar accounts or numbers, verify the sender’s identity independently, authorize only trusted applications, and review and revoke permissions in security settings. Anyone who suspects a compromise is asked to report it to the local FBI field office or the IC3 at ic3.gov. Removing the malicious application through the provider’s security settings is the step that ends the access; the advisory says in so many words that the password change is not.
The mechanics differ by provider. On Google accounts, Google’s help page says linked apps can be reviewed and removed at myaccount.google.com/linkedapps, and that a revoked app can no longer reach the data, though its developer may keep what it already collected and may have to be asked to delete it. Google also lets users report apps they believe are misusing account data. On Microsoft accounts, the company points individuals to myapps.microsoft.com and administrators to the Entra admin center or the Remove-MgOauth2PermissionGrant PowerShell cmdlet.
The sector that has relayed the warning most visibly is health care. The American Hospital Association passed the FBI’s alert to members on September 9, noting that messages arrive through commercial messaging apps and that approving the pop-up gives the attacker high-level access to a malicious app able to read and send email.
Detection is the harder half for organizations. Microsoft’s guidance tells administrators to search the audit log for “Consent to application” events and check whether the admin-consent flag is set to True, and it offers a script, Get-AzureADPSPermissions.ps1, that inventories every OAuth app and permission across a tenant. A month after the FBI’s advisory, the Bureau’s text still gives no count of how many accounts carry a grant the owner never meant to give.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview