logo

FBI Alert: OAuth Consent Phishing is Targeting Users of Messaging Apps

ID: ebf0c43c-8865-51ca-9e95-195808e823c2

STIX ID: report--ebf0c43c-8865-51ca-9e95-195808e823c2

Feed Name: KnowBe4 Blog

Threat Score
70/100

Date Published: 2026-09-11

Date Updated: 2026-09-12

Author: KnowBe4 Team

...
...

**FBI advisory on OAuth consent phishing:** The FBI warns of an active campaign where attackers use social engineering and malicious OAuth application consent links—often sent via commercial messaging apps and impersonating trusted figures—to obtain persistent, high-level access to victims' accounts without passwords or MFA; once granted, access remains until tokens are revoked, allowing attackers to read/send emails and access sensitive data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.