NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

FBI Raises Alarm About OAuth Consent Phishing Activity

The Federal Bureau of Investigation (FBI) has issued a warning about ongoing phishing activity involving a sophisticated technique known as OAuth consent phishing. Since late 2025, the FBI has observed malicious cyber actors using OAuth consent phishing in targeted attacks on prominent individuals, their family members, and personal acquaintances to gain persistent access to their accounts.

Similar to other forms of targeted phishing, the campaign involves impersonation of a trusted entity and tricks the victim into granting access to their account; however, this approach does not require the victim to disclose their username and password. The technique relies on OAuth, a commonly used authorization framework that allows websites and web applications to request access to a user’s account on another application, without exposing their login credentials.

With OAuth consent phishing, an attacker creates a malicious application and registers it with a legitimate OAuth provider. The application is configured with high-level privileges, such as the ability to access contacts, read and write emails, send emails on the user’s behalf, and more. The attacker then contacts the targeted individual via email or text and attempts to trick them into initiating the consent process.

In this campaign, the attackers typically impersonate publicly known personalities, government officials, journalists, and other high-profile individuals via a commercial messaging application (CMA). For instance, the individual is invited to take part in an event and must first verify their identity using the malicious but seemingly legitimate application.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

If the victim responds, they are presented with a legitimate permission request screen, such as for Microsoft 365, Google, or another legitimate cloud service. If the victim approves the request by clicking Allow, they provide their consent to the legitimate cloud service, which authorizes the malicious application to have the stated permissions through the provider’s authorization mechanism. The attacker is able to perform a range of malicious activities and access sensitive data without having to obtain the user’s password, and the technique bypasses multifactor authentication controls.

In practice, many users will not be aware that they have been successfully phished and will take no action. Should the victim smell a rat and change their password after granting access, the OAuth authentication token remains valid after the password change and will continue to provide the attacker with the previously granted permissions. The permissions must be revoked by removing the malicious app via the victim’s security settings.

The FBI advises users to be wary of this form of phishing and of any communications from unfamiliar phone numbers, accounts, or senders not in their contact list. Before taking any action in response to an unsolicited communication, users should first verify the identity of the sender and should only grant authorization to trusted applications. Even when the application is trusted, the requested permissions should be carefully assessed.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist