The FBI wants you to stop reflexively clicking Allow on Google and Microsoft permission screens.
The agency's Internet Crime Complaint Center issued a public warning this week about OAuth consent phishing, a technique where attackers register a malicious app with a legitimate platform, then message targets while posing as journalists, officials, or other known figures. The message includes a link to what looks like a shared document. That link goes to a real Google or Microsoft login page asking the user to grant the app permission to their account. Click approve, and the attacker gets an access token that can read and send email, no password required.
This matters because the usual advice - change your password - does nothing here. The token keeps working until someone manually revokes it in the app's account security settings, a step most people don't know exists. It also matters because the phishing link itself points to a real Google or Microsoft domain, which is exactly the kind of thing browser warnings and password managers are built to trust.
The technique isn't new - security researchers have tracked it for more than a year - but an FBI bulletin naming "prominent victims" and their family members suggests it has moved from theoretical risk to active problem.