< Back to all clusters
[CRIME] · United States, Poland · 3 sources

started · updated

FBI warns of OAuth consent phishing attacks

The FBI has issued a warning regarding a growing campaign of OAuth consent phishing. In this method, cybercriminals do not steal passwords directly. Instead, they impersonate government officials, media representatives, or other well-known figures to contact targets via messaging apps.

Attackers send links to controlled services that lead victims to legitimate login pages, such as Google or Microsoft. Once the user logs in, they are prompted to grant specific permissions to a malicious application. By clicking ‘Allow’, the user provides a digital permit that enables criminals to access private data, such as emails or files, without ever needing the account password.

Separately, in Poland, the Central Bureau for Combating Cybercrime (CBZC) has dismantled a criminal group involved in internet fraud. The group used hijacked social media profiles and fake advertisements to send phishing links. These links redirected victims to fraudulent sites to steal payment data, specifically BLIK codes, which were then used to embezzle funds.

Entities

Central Bureau for Combating Cybercrime · FBI · Google · Microsoft