{
  "id": 5280456,
  "title": "OAuth Consent Phishing: The Attack a Password Change Does Not Fix",
  "url": "https://urgent.news/2026/09/03/oauth-consent-phishing-the-attack-a-password-change-does-not-fix",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-03T08:07:27.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/tuxxin/oauth-consent-phishing-the-attack-a-password-change-does-not-fix-1dle"
  },
  "original_language": "en",
  "account": "The FBI's Internet Crime Complaint Center has issued a warning about a phishing attack that can bypass password changes and multi-factor authentication. This attack doesn't manipulate passwords or MFA, but instead targets a less-protected OAuth consent process. Users often unknowingly grant permission to apps during the OAuth flow, which allows the app to access their data without needing their password. The FBI explains that the damage done by this attack can only be undone by removing the consent grant from the app's connected applications settings, rather than changing the password or verifying MFA. The attack is typically launched through fake messages from impersonating individuals like government officials or event coordinators, asking the user to review documents or confirm attendance. The attack is especially dangerous because the compromised OAuth token can remain valid for months, granting the attacker ongoing access to the user's data. The warning emphasizes the importance of regularly auditing granted permissions and revoking access to apps that are no longer needed or trusted. This process involves checking connected applications lists on platforms like Google, Microsoft, LinkedIn, GitHub, Dropbox, Slack, Zoom, and Meta, and revoking permissions for any unused or suspicious apps. The FBI advises users to revoke the grant immediately, change their password afterward, and then review any suspicious login activity or forwarded emails. The warning concludes by urging users to periodically review their OAuth consent settings, as a simple two-minute audit can significantly reduce the risk of this type of attack.",
  "summary": "The FBI's Internet Crime Complaint Center published PSA I-090126 on September 1, 2026, and it describes an attack that quietly defeats the two things most people rely on: changing your password, and having multi-factor authentication turned on. Neither one helps here. That is not a flaw in either — it is that this attack never touches your password at all. What consent phishing actually is You…",
  "key_points": [
    "Phishing attack bypasses password changes and MFA",
    "Users unknowingly grant app permission during OAuth flow",
    "Damage undone by removing consent grant, not password"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}