Malicious Cyber Actors Gain Access to Victim Accounts Through Consent Phishing

Imported from official source

Alert

Cybersecurity Classified by Officially

Since late 2025, malicious cyber actors have been targeting prominent victims, their family members, and personal acquaintances by directly messaging personal accounts with malicious links leveraging a technique known as "OAuth consent phishing."

Recently observed activity includes impersonating government officials, media, and other publicly known personalities on a commercial messaging application (CMA) and soliciting the targeted individual to access a malicious link under the guise of a file sharing service through an application under the malicious actor's control. Previous phishing campaigns have also impersonated event coordinators and planners, who sent malicious links to targets under the guise of an invitation to an event and the need to verify the target's identity through a malicious application under the actor's control.

Historically, spear phishing efforts focused on social engineering ruses with links or access to malicious credential harvesting sites or malware deployment to gain access to target accounts or devices. OAuth consent phishing provides actors with persistent access to a target's account because once permission is obtained, it can only be revoked by the victim invalidating the token in their application security settings; not by changing the password.

This is an extract. The publication continues at the source.

Read the original at the source: https://www.ic3.gov/PSA/2026/PSA260901

Officially imported this from Internet Crime Complaint Center’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Internet Crime Complaint Center — imported from official source
Official source
https://www.ic3.gov/PSA/rss RSS
Imported
September 24, 2026 09:30
Versions
1 recorded
Identity
260901

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.