Clicking 'Allow' on a Google and Microsoft permission screens could give hackers access to your entire account, FBI warns
OAuth consent phishing is a thing and the FBI is worried.
The Federal Bureau of Investigation (FBI) has issued a warning about a new type of phishing attack that can compromise entire online accounts. These attacks rely on users granting permission to malicious apps during legitimate permission prompts on well-known platforms like Google and Microsoft. Once granted, the attackers can read emails, change passwords, and send messages to contacts without needing the user's password.
This technique, known as "OAuth consent phishing," has been around for over a year and has gained popularity, prompting the FBI to issue a public service announcement through its Internet Crime Complaint Center (IC3). OAuth (Open Authorization) enables apps to access user accounts on other services without the need for passwords.
For instance, when a user installs an app and clicks "Continue with Google," they are asked if they allow the app to access their email. If they agree, Google gives the app a special access token, allowing it to access the user's Google account without ever seeing their password.
To execute an OAuth attack, threat actors must first trick the platform provider (such as Google or Microsoft) into registering their malicious app. They then reach out to their targets through instant messaging, pretending to be authoritative figures like government officials or media personalities. The attackers send a link that appears to be a document, redirecting the victim to a legitimate service where they are asked to grant permissions to the malicious app.
If the user approves, the attackers gain access to the user's email accounts, enabling them to perform various malicious activities. The only way to remove this threat is to revoke the access token given to the app, which can be done in the application's security settings.
The FBI did not disclose the identities of the threat actors or their targets, except to say that they were "prominent victims." They also mentioned that family members were at risk.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.