The FBI warns that scammers are hijacking online accounts through a fake app-permission trick a password change won’t undo.

The FBI’s Internet Crime Complaint Center issued a public warning this week about a scam technique called OAuth consent phishing, in which criminals trick a victim into granting a fake app access to their email or file storage account, then keep that access indefinitely, even after the victim changes their password. The scam has been active since late 2025 and has focused on high-profile targets and the people around them, but the underlying trick works the same way against anyone who uses a Google, Microsoft, or similar online account, which describes most people managing retirement paperwork, tax records, or online banking today.

How the FBI Says OAuth Consent Phishing Works

According to the FBI’s September 1 advisory, malicious actors have been directly messaging people’s personal accounts, often on commercial messaging apps, while impersonating government officials, journalists, or other publicly recognizable figures. The message asks the target to click a link to review a document or access a file-sharing service. That link leads to a real, legitimate login page, Microsoft or Google’s actual sign-in screen, so the victim enters their real credentials and nothing is stolen at that stage. The danger comes next: a pop-up asks the victim to “allow” a third-party application to access their account. If the victim clicks allow, the scammer’s application gains standing permission to read and send emails, access files, and act on the account’s behalf, all without ever touching the victim’s password.

OAuth is the authorization framework that legitimately lets one app connect to another, the same technology behind “log in with Google” buttons on countless websites. The FBI’s warning is not that OAuth itself is unsafe, but that scammers are exploiting the trust built into that legitimate system by registering malicious applications and disguising them as identity-verification tools or file-sharing services.


Free retirement updates: Keep more of your Social Security and savings with plain-English updates on the changes, deadlines, and costly mistakes retirees miss. Subscribe free.

Why a Password Change Does Not Fix This

The detail that sets this scam apart from ordinary phishing is persistence. Once someone approves the fake application’s permission request, the FBI explains, the scammer holds a standing access token, not a stolen password. Changing the account password does nothing to revoke that token; the only way to cut off the scammer’s access is to go into the account’s own security or app-permissions settings and manually remove the malicious application. Someone who falls for this scam and simply resets their password afterward, believing the problem is solved, can remain exposed for weeks or months without realizing it, while the scammer continues reading messages, downloading files, or watching for financial information that passes through the account.

For anyone managing a Medicare enrollment, a Social Security online account, or brokerage statements through email, that kind of silent, ongoing access is particularly costly. A scammer sitting inside an email inbox can watch for password-reset emails from a bank, intercept two-factor authentication codes sent by email, or simply gather enough personal detail, a Social Security number on a tax document, an account number on a statement, to attempt identity theft weeks after the original message was ever opened.

Who the FBI Says Is Being Targeted

The advisory notes that recent campaigns have impersonated government officials, media figures, and other publicly known personalities, and have also posed as event coordinators sending fake invitations that require “identity verification” through a malicious app. The FBI’s warning specifically calls out that actors are messaging not just prominent individuals but also their family members and personal acquaintances, meaning someone does not need to be famous or wealthy to be targeted; being connected to someone the scammers are impersonating, or simply receiving a convincing unsolicited message, is enough.

The FBI recommends treating messages from unfamiliar phone numbers or accounts, or from people outside a known contact list, with increased scrutiny, and independently verifying a sender’s identity through a separate, trusted channel before clicking any link tied to a document review or file-sharing request. The agency’s core advice is simple: only grant account permissions to applications the recipient already knows and trusts, and never approve an access request that arrives through an unsolicited message.

Signs of a Compromised Account After a Password Reset Fails

Anyone who wants to check whether an unfamiliar application currently has access to their Google or Microsoft account can do so without waiting for a problem to appear. Google account holders can review connected apps under the “Security” section of their account settings, listed as “Third-party apps with account access,” and Microsoft account holders have a similar “App permissions” page. Any application that is unrecognized, or that was granted access after an unexpected message or pop-up, should be removed immediately. This kind of periodic check takes only a few minutes and costs nothing, unlike the alternative of discovering months later that a scammer had standing access to tax records or financial correspondence the whole time.

For anyone who may have already granted access to a malicious application, the FBI’s advisory directs victims to report the incident to their local FBI field office or to the Internet Crime Complaint Center at ic3.gov, including any screenshots of the original message and the permission request. Reporting does not undo access that has already been granted, but it does help the FBI track and take down the fraudulent applications behind these campaigns.

This article was produced with the assistance of AI and reviewed by The Financial Wire editorial team.

The Financial Wire

Warren Cohen

Source