{
  "id": 5350923,
  "title": "Clicking 'Allow' on a Google and Microsoft permission screens could give hackers access to your entire account, FBI warns",
  "url": "https://urgent.news/2026/09/03/clicking-allow-on-a-google-and-microsoft-permission-screens-could",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-03T14:45:00.000Z",
  "source": {
    "name": "TechRadar",
    "slug": "techradar",
    "url": "https://www.techradar.com/pro/security/clicking-allow-on-a-google-and-microsoft-permission-screens-could-give-hackers-access-to-your-entire-account-fbi-warns"
  },
  "original_language": "en",
  "account": "The Federal Bureau of Investigation (FBI) has issued a warning about a new type of phishing attack that can compromise entire online accounts. These attacks rely on users granting permission to malicious apps during legitimate permission prompts on well-known platforms like Google and Microsoft. Once granted, the attackers can read emails, change passwords, and send messages to contacts without needing the user's password.\n\nThis technique, known as \"OAuth consent phishing,\" has been around for over a year and has gained popularity, prompting the FBI to issue a public service announcement through its Internet Crime Complaint Center (IC3). OAuth (Open Authorization) enables apps to access user accounts on other services without the need for passwords. For instance, when a user installs an app and clicks \"Continue with Google,\" they are asked if they allow the app to access their email. If they agree, Google gives the app a special access token, allowing it to access the user's Google account without ever seeing their password.\n\nTo execute an OAuth attack, threat actors must first trick the platform provider (such as Google or Microsoft) into registering their malicious app. They then reach out to their targets through instant messaging, pretending to be authoritative figures like government officials or media personalities. The attackers send a link that appears to be a document, redirecting the victim to a legitimate service where they are asked to grant permissions to the malicious app. If the user approves, the attackers gain access to the user's email accounts, enabling them to perform various malicious activities. The only way to remove this threat is to revoke the access token given to the app, which can be done in the application's security settings.\n\nThe FBI did not disclose the identities of the threat actors or their targets, except to say that they were \"prominent victims.\" They also mentioned that family members were at risk.",
  "summary": "OAuth consent phishing is a thing and the FBI is worried.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "TechRadar",
        "title": "IT helpdesk impersonation hits Microsoft Teams once again, with the hackers hiding their activity within legitimate tools",
        "url": "https://urgent.news/2026/09/03/it-helpdesk-impersonation-hits-microsoft-teams-once-again-with-the",
        "published": "2026-09-03T16:55:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}