FBI Warns of OAuth Consent Phishing Tricks

Security Week Feed · Medium sophistication
Last updated September 11, 2026

A SecurityWeek roundup highlights multiple real-world scams and campaigns where attackers trick people rather than “hack” systems directly. Notable items include OAuth “consent phishing” (getting users to approve a malicious app’s access), and phishing-evasion using invisible Unicode characters inserted into financial lure words.

Key findings

  • Microsoft observed a phishing-related evasion campaign (Feb–Jun) using invisible Unicode tag characters inserted into financial lure terms such as “funding,” generating up to 2.37 million messages per day.
  • The FBI warned that attackers are using OAuth consent phishing to get persistent access without stealing passwords by impersonating trusted figures and pushing victims to approve a malicious app.
  • US banking customers were targeted via fake financial websites and sponsored search results that redirected victims into credential-harvesting phishing pages.
  • A former AT&T employee was sentenced for SIM swapping that enabled account takeovers and attempted losses near $600,000 (insider-enabled fraud).

Who’s being targeted

  • Commonly targeted roles: All employees, Executives, Finance, IT / IAM (identity and access management), Helpdesk / Service desk.
  • Affected industries: Finance / Banking, Telecommunications, Government.
  • Attack channels: email, website.
  • Impersonated: A trusted figure (e.g., internal leader/vendor contact), A financial institution (bank).

Awareness takeaways

  • Treat “app permission” requests as high-risk and verify before approving OAuth consent (especially if it offers access to email/files).
  • Be cautious with search ads for sensitive logins (like banking). Navigate using saved bookmarks or manually typed known URLs.
  • Don’t assume security tools will catch every phishing attempt, attackers may use evasion tactics such as invisible Unicode in lure terms.

Red flags to watch for

  • Unexpected request to approve app permissions
  • Legitimate-looking permissions that grant broad access to email/files
  • Request comes from an impersonated “trusted figure” rather than a known internal process
  • Sponsored/search ad result leads to a lookalike site
  • Bank login page URL/domain doesn’t match the known official domain
  • Unexpected prompts or page design inconsistencies during login
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You know that box that says, “This app wants to access your email and files”? That click can hand over your whole account. FBI’s warning: attackers use OAuth consent phishing. They impersonate a manager or vendor, email you, “Please approve this app so I can share the documents,” then a legit-looking Microsoft-style screen asks to read your mail and files, no password theft needed. At the same time, Microsoft saw millions of phishing emails using invisible Unicode in words like “funding” to dodge filters, and fake bank sites hiding behind sponsored search ads that steal logins when you search for your bank. If any email or pop-up asks you to approve an app for email or file access, stop and forward it to the security team before you click Approve, one check now beats handing over your account for good.

Similar attacks

Russian Hackers Used AI to Evolve Phishing & Malware

Russian Hackers Used AI to Evolve Phishing & Malware

Anthropic says it disrupted a Russian state-linked campaign that used Claude to continuously rebuild malware when security tools detected it. The group (GTG-20006, linked to Midnight Blizzard/APT29) ran phishing and other human-targeted schemes, including device-code token theft against Microsoft…

September 11, 2026
Russian Clusters Hijack Accounts via OAuth & WhatsApp

Russian Clusters Hijack Accounts via OAuth & WhatsApp

Google says multiple suspected Russia-linked espionage clusters targeted academics, government, and defense-related personnel by abusing legitimate sign-in features instead of using obvious fake login pages. The campaigns used realistic lures (file sharing, conference invites, and “secure WhatsApp”…

August 20, 2026
“Half-Click” Zimbra Email Attack Steals 90 Days

“Half-Click” Zimbra Email Attack Steals 90 Days

CISA warns a Russian state-sponsored group (“Laundry Bear,” tracked by Microsoft as “Void Blizzard”) is compromising some unpatched Zimbra email accounts when users merely open or preview a specially crafted email. The hidden code can steal passwords, MFA-related tokens, and up to 90 days of…

August 14, 2026
Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026
Device Code Phishing: MFA Bypass at Scale

Device Code Phishing: MFA Bypass at Scale

This article describes real-world “device code phishing” campaigns where victims are tricked into approving an OAuth device login, granting attackers access without stealing passwords. It highlights rapid criminal adoption via phishing-as-a-service kits and notes heavy targeting of Microsoft…

July 31, 2026
Phishers Abuse DocuSign, Rewards, and “Verification”

Phishers Abuse DocuSign, Rewards, and “Verification”

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials or install remote-control tools. The common theme is trust abuse: messages and web pages look legitimate, then push users to log in, click…

July 28, 2026