Phishing

Clicking ‘Allow’ on a Google and Microsoft permission screens could give hackers access to your entire account, FBI warns | Daily Reports Online

Share


  • FBI warns of rising OAuth consent phishing attacks exploiting legitimate app permissions
  • Victims tricked into granting malicious apps access, enabling email reading and sending
  • Password changes don’t help; users must revoke tokens in app security settings

Hackers found a way to access your data, read your messages, and even send emails to your contacts, without ever needing your password or other login credentials. All they need from you is a single click on a completely legitimate, well-known platform.


The technique is called “OAuth consent phishing”. It’s been around for more than a year and it’s gotten popular to a point where even the FBI is taking note. Earlier this week, the law enforcement agency issued a new public service announcement, via its Internet Crime Complaint Center (IC3), warning Americans about the threat.


Similar Posts