TL;DR: On September 1, 2026 the FBI's IC3 warned of an OAuth consent phishing campaign active since late 2025. Criminals contact prominent people, their relatives and acquaintances on messaging apps, then send a genuine-looking permission request. Approving it gives lasting access that bypasses passwords and multi-factor authentication and is not removed by changing the password.

👉 Check my digital footprint — free 30-second check →

What the alert says

In a public service announcement dated September 1, 2026, the FBI Internet Crime Complaint Center (IC3) described a campaign that has run since late 2025. It targets prominent individuals, their family members and personal acquaintances through commercial messaging apps.

The criminals pose as government officials, media personalities, public figures or event coordinators. They send a link that opens a legitimate-looking provider screen asking the user to grant a malicious application access to the account.

Why a strong password does not help

The FBI explains that once the user approves the request, the attacker holds persistent access. The technique bypasses both passwords and multi-factor authentication. The alert states that the access can be revoked only by invalidating the token in the application's security settings, not by changing the password.

In other words, the victim has handed over a key rather than had a lock picked.

Red flags and what to do

The FBI advises scrutinizing messages from unknown numbers or accounts, verifying the sender independently, and approving only applications you trust. If you already approved something suspicious, open your account's security or connected-apps settings and remove it immediately. Changing the password alone will not end the access.

This is a close cousin of other approval-based tricks. Our guides to remote access scam recovery and tech support scam recovery cover the cases where a stranger gains control of a device, and what to do after a scam, wherever you live gives general next steps after any scam.

Where to report

Contact your local FBI field office or file a report at FBI Internet Crime Complaint Center (IC3), and include screenshots of the messages and permission screen. If a work or financial account was exposed, notify the provider and your bank. The steps in how to report a scam to the IC3 explain what to include.

Frequently Asked Questions

What is OAuth consent phishing?

It is a technique in which a victim is tricked into approving a permission request for a malicious application through a legitimate-looking provider screen, which gives the attacker persistent account access.

Does two-factor authentication stop it?

According to the FBI, the technique bypasses both passwords and multi-factor authentication.

Will changing my password remove the attacker?

No. The FBI says access can only be revoked by invalidating the token in the application's security settings.

Who is being targeted?

The FBI says prominent individuals, their family members and personal acquaintances, contacted on commercial messaging apps.

Sources

Related Reading