Malicious Cyber Actors Gain Access to Victim Accounts Through Consent Phishing


Since late 2025, malicious cyber actors have been targeting prominent victims, their family members, and personal acquaintances by directly messaging personal accounts with malicious links leveraging a technique known as “OAuth consent phishing.”

Recently observed activity includes impersonating government officials, media, and other publicly known personalities on a commercial messaging application (CMA) and soliciting the targeted individual to access a malicious link under the guise of a file sharing service through an application under the malicious actor’s control. Previous phishing campaigns have also impersonated event coordinators and planners, who sent malicious links to targets under the guise of an invitation to an event and the need to verify the target’s identity through a malicious application under the actor’s control.

Read more…
Source: U.S. Federal Bureau of Investigation Cyber Division


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Law firm Kirkland sued in class action over MOVEit data breach

    June 10, 2024

    U.S. law firm Kirkland & Ellis, the world’s largest law firm by revenue, has been pulled into U.S. litigation over a wide-ranging data breach linked to a file transfer tool that compromised data at hundreds of organizations. A proposed class action, opens new tab filed on Friday accused Kirkland and several other companies, including health insurer ...

  • A New Branch of the Armed Forces is Critical to Addressing Cyber Threats to America

    June 7, 2024

    The concept of a United States Cyber Force has been proposed in one form or another for more than a decade. Perhaps the most well-known advocate is ADM James G. Stavridis, retired NATO Supreme Allied Commander and the former Commander of both European and Southern Commands, who has highlighted many of the salient obstacles to the ...

  • FBI urges LockBit ransomware victims to reach out after securing thousands of decryption keys

    June 7, 2024

    The FBI revealed it has thousands of decryption keys that can unlock data encrypted by the LockBit ransomware. The agency’s Assistant Director for the Cyber Division, Bryan Vorndran, confirmed the news during the 2024 Boston Conference on Cyber Security, and has invited all past LockBit victims to reach out and try to unlock their files. Read more… Source: ...

  • Scammers Defraud Individuals via Work-From-Home Scams

    June 4, 2024

    The FBI warns of scammers offering victims fake work-from-home jobs, typically involving a relatively simple task, such as rating restaurants or “optimizing” a service by repeatedly clicking a button. The scammers pose as a legitimate business, such as a staffing or recruiting agency,and may contact victims via an unsolicited call or message. Scammers design the fake ...

  • ‘People’s lives are at risk’: Ascension ransomware attack going on nearly three weeks

    May 29, 2024

    A ransomware attack on a major US hospital network that began three weeks ago is endangering patients’ health as nurses are forced to manually enter prescription information and work without electronic health records, nurses at two hospitals affected by the cyberattack told CNN. “It’s putting patients’ lives in danger,” said a nurse who works at Ascension ...

  • 5 Reasons to Attend Cyber Security & Cloud Congress North America 2024

    May 24, 2024

    Explore the forefront of enterprise technology at the Cyber Security & Cloud Congress North America. Delve into the entirety of the Cyber Security & Cloud Ecosystem and unravel the practical and triumphant application of Cyber Security & Cloud. Returning to North America on June 5-6, 2024, at the esteemed Santa Clara Convention Center, the globally renowned ...