
Changing your password used to be the go-to fix whenever you suspected your email had been compromised. According to a new federal warning, that fix no longer works against a scam quietly spreading across the country, one that lets criminals keep reading, writing, and sending your emails long after you've locked your account down with a fresh password.
How the Scam Tricks Victims Into Handing Over Access
The Federal Bureau of Investigation issued the warning about a technique known as OAuth consent phishing, according to Cleveland.com. Rather than stealing a password outright, a cyber actor creates an app registered with a legitimate OAuth provider, then poses as a government official, a media organization, or a publicly known personality to reach a target. The scammer sends a link through a direct message or email, often asking the target to review a document. Once the target clicks the link, they receive an OAuth permission request, and if they approve it, the app instantly gains access to their email account.
OAuth itself is not the problem. It's a legitimate permission screen used by services such as Google and Microsoft, letting apps access a user's data without the user ever handing over sign-in credentials or a password, per the same report. The trouble starts when a cyber actor configures a malicious app to request permissions to read and write a user's files and emails, and the target grants that access without realizing what they've just done. The Internet Crime Complaint Center, known as IC3, has been tracking this exact campaign since late 2025, according to an Internet Crime Complaint Center alert released September 1.
Why a New Password Doesn't Fix It
This is the part that catches victims off guard. Once a malicious app has been granted OAuth permissions, a cyber actor bypasses the passwords and multi-factor authentication protecting the email account entirely. Changing the password does not stop the scammer from accessing the victim's email, because the app's access token operates independently of the password and stays valid until it's specifically revoked.
Consent phishing lures aren't limited to strangers cold-emailing random targets. As CyberScoop reports, scammers behind this campaign specifically target personal accounts of high-profile individuals, their family members, and personal acquaintances on commercial messaging apps and email, using lures like draft article reviews, identity verification requests, and event invitations. The FBI's warning notes the scam targets people across the country, not any single region or industry.
The Technical Mechanics Behind the Access
Instead of setting up fake login pages to steal credentials the old-fashioned way, threat actors register malicious applications with standard identity providers like Microsoft and Google, configuring the apps to request permission to read, write, and send emails via background API refresh tokens, according to a report from Help Net Security. Technical guidance from the Cybersecurity and Infrastructure Security Agency explains that stolen application access tokens allow attackers to make direct REST API calls, letting them search emails, harvest contacts, and even trigger password reset routines on secondary accounts connected to the victim's inbox, according to the Cybersecurity and Infrastructure Security Agency.
Why Standard Cyber Defenses Fall Short
Cybersecurity experts emphasized following the FBI warning that traditional perimeter defenses, including firewalls, endpoint antivirus, and multi-factor authentication, are ineffective against consent phishing because the attack exploits the cloud identity authorization layer rather than credentials, according to Long Island Life & Politics. That distinction matters because standard consumer security advice has emphasized changing passwords and enabling multi-factor authentication for decades, creating a false sense of safety for anyone unaware that OAuth tokens work independently of both.
How to Check and Remove a Malicious App
The fix requires a different move than the usual password reset. To remove an attacker's access after approving a malicious request, victims must navigate to their Google or Microsoft account security settings under Connected Apps or Third-Party Apps With Account Access and manually invalidate or revoke the specific app's token, according to Gizmodo. Victims must either delete the app entirely or invalidate its token in those application security settings; a password change alone leaves the door wide open.
The FBI advises extra caution with communications from unfamiliar phone numbers, accounts, or businesses, and recommends checking that an app is legitimate before granting it OAuth permission. Organizations face a parallel challenge. Cybersecurity recommendations for enterprise networks advise IT administrators to restrict end-user consent settings in Google Workspace and Microsoft 365 so employees cannot grant account access to unverified third-party applications without admin review, according to a video explainer covering the topic.
The Broader Scale of Email-Based Cybercrime
The FBI's IC3 logged over 1 million complaints and $20.8 billion in total reported cybercrime losses in its 2025 Internet Crime Report, released in April 2026, with Business Email Compromise accounting for $3.04 billion across nearly 25,000 incidents, according to Red Sift. Total cybercrime complaints filed with federal authorities increased 17.3% year-over-year in 2025, while standalone phishing losses surged to $215.8 million as identity-based account takeover techniques grew more prevalent, per SpyCloud.
There is at least one silver lining buried in the numbers. Federal law enforcement recovered or froze over $507 million in fraudulent domestic wire transfers in 2025 through the FBI Recovery Asset Team's Financial Fraud Kill Chain initiative, which works with financial institutions to hold fraudulent transfers before funds leave the country, following rapid victim reports, according to CNiC. Speed matters, and the same principle applies to consent phishing: the FBI requests that anyone who suspects they've been targeted report the incident to their local FBI field office or to the Internet Crime Complaint Center.









