FBI Warns OAuth 'Allow' Clicks Can Give Hackers Full Access to Google and Microsoft Accounts
FBI warns that one 'Allow' click can let hackers take over Google or Microsoft accounts; password reset does not fix it.
OAuth, or Open Authorization, is an internet standard that lets users grant outside apps access to data held by another service without revealing their passwords. When a user selects “Continue with Google” and approves an app’s request, the service issues an access token that allows the app to interact with the user’s account. Attackers have turned this convenience into a phishing vector by registering malicious apps on legitimate platforms and then luring victims into approving them.
In an OAuth consent phishing attack, a threat actor first gets a malicious app registered on a platform such as Google or Microsoft. The attacker then contacts the victim through instant messaging while impersonating government officials, media figures or other prominent personalities, and sends a link to what looks like an ordinary document. The link redirects the victim to a legitimate service, where the victim is asked to grant permissions to the malicious app. If the victim clicks “Allow,” the attacker can read messages, send emails and take other actions in the compromised account without ever seeing a password.
The FBI stressed that changing a password after such a compromise is not enough. To stop the threat, users must revoke the access token that was granted to the malicious app, which is done through the application’s security settings.
The FBI did not specify who the attackers were or who they targeted beyond saying the victims were “prominent.” It added that family members of those victims were also being targeted.