Skip to content

This article features deals sourced directly by Gizmodo and produced independently of the editorial team. We may earn a commission when you buy through links on the site.

Deals

Hackers stopped attacking passwords. They’re attacking your consent instead.

Cybersecurity advice has been the same for two decades. Use a strong password. Turn on two-factor authentication. Change your credentials if something feels off. A new phishing wave that federal investigators are actively warning about does something none of that guidance was built for: it doesn't touch your password at all. Instead, it tricks you into clicking "allow" on a legitimate-looking login screen that grants an attacker persistent access to your email, files, and cloud services. Password changes don't revoke that access. Multi-factor authentication doesn't stop it.

By

Reading time 4 minutes

What the FBI actually described

The warning came from the FBI’s Internet Crime Complaint Center in a September 1 public service announcement (PSA I-090126). The advisory describes a technique called OAuth consent phishing, which the Bureau has been tracking since late 2025 and now considers active against prominent individuals, their families, and personal contacts. The FBI’s own language is blunt: it calls the technique “a deceptive, sophisticated approach to access user accounts without requiring a password.”

OAuth is the framework behind every “Sign in with” or “Continue with” button you’ve ever clicked on a major platform. It exists so third-party apps can request access to your account without you handing over your actual password. Legitimate uses are everywhere: a calendar app reading your calendar, a photo editor pulling images from your cloud storage, a productivity tool accessing your inbox to draft replies. The attack weaponizes exactly that flow.

Why changing your password won’t fix this

This is the part that flips the usual playbook. In a normal phishing attack, you enter your credentials into a fake login page, the attacker steals them, you notice something wrong, you reset your password, and the attacker loses access. That model doesn’t apply here. Because the attacker never had your password in the first place. What they have is an OAuth authorization token, granted by you when you clicked “allow” on the malicious app’s permission screen.

The FBI’s advisory spells it out: “Once permission is obtained, it can only be revoked by the victim invalidating the token in their application security settings, not by changing the password.” That means the standard advice everyone knows by heart, the advice IT teams have been giving for twenty years, is exactly the wrong response. Password resets accomplish nothing. Fresh 2FA codes accomplish nothing. The only way out is to hunt down the malicious authorization in your account’s security dashboard and manually revoke it, which most users have never opened in their lives.

Block phishing domains with NordVPN

How the attack actually plays out

The mechanics are simpler and more convincing than most phishing schemes. An attacker impersonates a trusted contact or service, usually through email or a messaging platform, and sends a link. The link opens a real, legitimate login page from a major platform you already use, exactly the one you’d expect. You sign in normally. But then the page asks you to approve an app you don’t recognize, requesting permissions like “read your emails” or “access your files.” You approve it because you just signed in, the domain looks correct, and the flow feels normal.

Behind the scenes, that approval hands the attacker a token with the permissions you just granted. They now have quiet, persistent access to your account, and every subsequent login you perform, every 2FA code you enter, changes nothing about their access. Security researchers tracking these campaigns have documented 10 to 15 new operations of this style every 24 hours in recent months, with several million attacks recorded over a single four-week window earlier this year. The kits behind the campaigns, sold under names like Kali365 and EvilTokens, lower the barrier for less-technical attackers to run these operations at scale.

Where NordVPN fits in the picture

No VPN can prevent a user from clicking “allow” on a consent screen they trust. That’s a human decision that no network-layer tool can override. What a well-designed security suite can do is block the malicious link before it ever loads in your browser, which cuts the attack chain earlier in the process. NordVPN‘s Threat Protection Pro, included in the higher-tier plans, maintains a continuously updated list of known phishing domains, malicious redirectors, and scam infrastructure, and blocks connections to them at the network level regardless of which app or browser triggered the request.

The Dark Web Monitor covers the other side of the problem. If an attacker does gain access to your inbox and starts exporting personal data, that data typically ends up on cybercrime forums within weeks. The monitor scans those forums for your email address and alerts you when it appears, which is often the first practical signal that something is wrong on an account you’re not actively watching.

Get NordVPN with Threat Protection

The Basic plan at $3.49/month

NordVPN’s Basic plan is currently available at $3.49/month, which works out to $94.23 billed once for 27 months of service (24 + 3 free). That is a 69% discount off the standard rate. Annual renewal continues at $139.08/year, cancelable from the account dashboard at any time.

The plan covers the core VPN across up to 10 devices with applications for Windows, macOS, Linux, iOS, Android, plus browser extensions and router installation. Upgrading to a higher tier adds Threat Protection Pro and Dark Web Monitor, which are the two features most directly relevant to the OAuth phishing wave the FBI is tracking.

Get NordVPN Basic at $3.49/month

30 days to test everything, no strings attached

NordVPN backs every plan with a 30-day money-back guarantee. If the service does not fit the way you use your devices, you can request a full refund within the first month. Refunds are processed through 24/7 chat support, and funds typically return within 5 to 10 business days depending on the payment method used.

That gives you a full month to install the apps, test the speeds on your home connection, and see how the phishing filter and dark web monitor behave against the actual attack traffic hitting your inbox. A note on the subscription: the $3.49/month rate applies to the first 27 months. Auto-renewal then kicks in at the standard annual rate. If you would rather renegotiate or cancel before renewal, set a reminder in your calendar 7 to 10 days before the renewal date.

Start a 30-day risk-free trial

Share this story

Sign up for our newsletters

Subscribe and interact with our community, get up to date with our customised Newsletters and much more.