Canadian Cyber Security Journal
SOCIAL:
Filed under: Trends

FBI Warns OAuth Consent Phishing Outlasts Password Resets

What Happened

The FBI’s Internet Crime Complaint Center issued a warning on September 1 describing an OAuth consent phishing campaign running since late 2025 and targeting prominent individuals along with their relatives and personal contacts. The technique sends a phishing message directing a victim to a genuine Google or Microsoft permission screen rather than a fake login page, and the victim grants a malicious application access to their account by clicking allow. No password gets stolen and no multi-factor prompt gets bypassed in the traditional sense, since the attacker never needs the victim’s credentials once the application token exists. Details are available from Help Net Security.

Why This Matters for Canadian Organizations

OAuth consent phishing defeats the two most common incident response reflexes, a forced password reset and enrollment in stronger MFA, since neither action revokes an already-granted application token. Executives, board members, and public officials sit among the highest-value targets for this technique across Canadian government, financial services, and critical infrastructure organizations, and an attacker holding lasting mailbox access to a senior official gains ongoing visibility into sensitive correspondence rather than a single point-in-time data grab. Federally regulated institutions operating under OSFI Guideline B-13 maintain identity and access management controls built around credential compromise scenarios, and this technique sits outside the model entirely, requiring security teams to add application consent auditing to their detection coverage rather than relying on password and MFA hygiene alone.

What to Do

Security teams should audit third-party application consent grants across Google Workspace and Microsoft 365 tenants on a recurring basis, not only after a suspected incident, and revoke any application no administrator recognizes or approved. Organizations supporting executives and public-facing officials should brief this group directly on the technique, since the lure depends on the target trusting a permission screen precisely because it appears on a legitimate provider domain. Incident responders investigating a suspected account compromise should check application consent grants alongside password and session logs, since a clean password reset provides no assurance an attacker’s access ended. Full guidance is available from Help Net Security and CyberScoop.

Enjoy this article? Don’t forget to share.