Money, explained for the rest of us.

Get our free daily email →

The FBI warns of a phishing trick that survives a password change

By

selective focus photography of person using smartphone

A federal cybersecurity warning issued this week describes a scam that keeps working even after a victim does the one thing security advice always recommends: changing the password. The FBI’s Internet Crime Complaint Center says cyber actors have been quietly gaining lasting access to people’s email and messaging accounts by tricking them into approving a permission screen, not by stealing a password at all.

What the September 1 FBI Alert Describes

An IC3 public service announcement, numbered I-090126-PSA and published September 1, 2026, says the activity has been going on since late 2025. Actors impersonate government officials, media figures and event planners on a commercial messaging app, then message a target directly with a link disguised as a file-sharing invitation or an event request that needs identity verification. The target isn’t asked to type a password into a fake login page, the classic phishing setup. Instead, clicking the link leads to a real login screen from a legitimate provider, followed by a permission request known as an OAuth consent prompt.

If the target clicks “allow,” they’ve granted a third-party application, one controlled by the scammer, standing access to read or send from their account, without ever handing over so much as a password. The full mechanism is laid out in the FBI’s alert.


Free retirement updates: One number can cost or save hundreds a month in retirement. The free Retirement Shield newsletter surfaces the ones worth knowing. Sign up free.

Why a New Password Doesn’t Fix It

This is the part of the alert worth sitting with. In an ordinary phishing scam, a stolen password is the whole prize, and changing that password locks the thief out immediately. OAuth consent phishing never touches the password at all. The access the scammer gets comes from a digital token, granted the moment “allow” was clicked, and that token keeps working independently of whatever the account’s password happens to be at any given time.

The FBI’s alert states it plainly: the permission “can only be revoked by the victim invalidating the token in their application security settings; not by changing the password.” Someone who suspects they’ve been compromised, resets their password, and considers the matter closed may still have an attacker quietly reading their email weeks later, because the actual door the scammer walked through was never locked by a password to begin with.

The One Setting That Actually Removes Access

Every major email and account provider keeps a page listing which outside apps currently have permission to touch that account, and that page is where this gets fixed. On a Google account, that’s the “third-party apps with account access” section under Security, documented on Google’s own account help pages. On a Microsoft account, the equivalent is the My Apps permissions portal, described on Microsoft’s support site. Anyone unfamiliar with an app name listed there, or who doesn’t remember approving it, can remove its access directly from that screen, which is what actually cuts off the connection.

Checking that list is a five-minute task worth doing even without a specific reason to suspect trouble, since a permission granted months or years ago to a forgotten app is exactly the kind of quiet access this scam depends on going unnoticed.

Spotting the Approach Before It Reaches the Consent Screen

Because the scam starts with a direct message rather than a mass email, the FBI’s mitigation advice focuses on the messenger, not just the link. The alert recommends treating messages from unfamiliar phone numbers or accounts, or anyone outside a known contact list, with extra scrutiny, and independently verifying a sender’s identity before clicking anything they’ve sent. A message claiming to be from an event coordinator, a journalist wanting a document reviewed, or an official needing identity verification is worth confirming through a channel the recipient controls, such as calling a known number or checking with a mutual contact, rather than through any link embedded in the message itself. The same caution extends past messaging apps: consent-phishing links have also turned up in ordinary email invitations and calendar requests, so the mitigation is about independently verifying whoever is asking, not about avoiding one specific platform.

A Warning That Landed in a Busy Alert Season for IC3

This PSA didn’t arrive in isolation. In the six weeks before the September 1 warning, IC3’s public alerts included a notice about scammers impersonating IC3 itself on July 20, guidance on swatting threats aimed at community members on August 4, a warning about actors targeting explicit content through sexual-exploitation schemes on August 10, and an alert about malicious actors targeting water and wastewater sector control systems on July 30. That pace shows how much of the bureau’s current public alert output is aimed at everyday consumer and community-facing threats rather than large-scale infrastructure attacks alone, and it’s a reminder that OAuth consent phishing is one entry in a much longer list of tactics the FBI is actively tracking this year.

IC3’s own numbers explain why the bureau keeps issuing these warnings in the first place. Reported losses from internet-enabled crime climbed to $16.6 billion in 2024, the bureau’s own published figures show, up from $12.5 billion the year before and more than double what victims reported just three years earlier. Anyone who believes they’ve clicked through to a consent screen and approved an unfamiliar app should revoke that access immediately and can also report the incident to their local FBI field office or through IC3.gov, keeping screenshots of the original message as part of the report.

This article was produced with AI assistance and reviewed by a human editor. Figures are linked to their primary sources; where a claim could not be verified from the public record, we say so.

More Financial Reading


Spotted an error? Tell us at [email protected]. We fix mistakes fast and in the open — see how we work on our standards page.

Get the money news that affects your wallet — free, every weekday morning.

Benefits, taxes, and savings, explained in plain English. Get the free newsletter.

Free from Retirement Shield. Unsubscribe anytime. We never ask for money.