FBI/IC3 PSA260901: OAuth Consent Phishing Campaign Targeting High-Profile Individuals via Commercial Messaging Apps — Threadlinqs Intelligence
As of 2026-09-01, FBI/IC3 PSA260901: OAuth Consent Phishing Campaign Targeting High-Profile Individuals via Commercial Messaging Apps is a high-severity phishing threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 9 indicators of compromise.
Threat ID: TL-2026-2286 · Severity: HIGH · Status: ACTIVE · Category: PHISHING
The FBI's Internet Crime Complaint Center (IC3, PSA260901, issued 2026-09-01) warns that since late 2025 threat actors have targeted prominent individuals, their family members, and acquaintances
On 2026-09-01 the FBI's Internet Crime Complaint Center (IC3) published Public Service Announcement PSA260901 warning of an active OAuth consent-phishing campaign, running since late 2025, that specifically targets prominent, high-profile individuals along with their family members and personal acquaintances. The attack begins with a direct message on a commercial messaging application (CMA) in which the actor impersonates a government official, journalist, media personality, event coordinator, or planner to establish a plausible pretext — for example, a request to review a draft article or verify an identity — before sending a link framed as a file-sharing invitation.
Unlike credential-phishing or classic AiTM (adversary-in-the-middle) attacks, the victim is not asked for a password. Clicking the link redirects the victim to the legitimate authorization/consent screen of a real identity provider (the FBI names Microsoft and Google), where they authenticate normally — completing any MFA challenge exactly as they would for a trusted login. The difference is what happens next: the victim is then asked to approve a permissions ('consent') request from an application under the attacker's control. If approved, the attacker's application receives an OAuth access/refresh token scoped to whatever permissions were granted (the FBI describes 'full visibility into the target's configured permissions,' enabling access to emails, files, and other sensitive data).
This is the defining danger the FBI calls out: because the token is a bearer credential issued by the identity provider directly to the attacker's registered application, it is functionally independent of the victim's password. It survives a password reset and can only be terminated by the victim explicitly finding and revoking the application's authorization in their account's app/security settings — a step most users do not know exists or think to take. The FBI states plainly that the technique 'bypass[es] both passwords and multi-factor authentication.'
The FBI PSA discloses no attribution, no named malicious application, domain, or other network/host IOC, and no confirmed victim count — it is a technique-and-targeting warning, not an incident-forensics report. This research therefore documents the disclosed campaign precisely as reported while drawing on parallel, independently-sourced reporting to ground the surrounding technique family: security researchers (Obsidian Security) have cataloged OAuth/consent-phishing as a growing attack class with at least five distinct patterns as of late 2025/2026 — device-code phishing, platform-hosted 'CoPhish' consent abuse inside a victim's own tenant, commodity attack kits (SquarePhish, Graphish) that a BleepingComputer/Infosecurity Magazine-reported wave since September 2025 attributes in part to the financially-motivated group TA2723 and the Russia-aligned UNK_AcademicFlare, admin-consent impersonation, and the browser-native 'ConsentFix' ClickFix variant. None of these named actors, kits, or campaigns is confirmed by the FBI to be the operator behind PSA260901's specific high-profile-individual targeting; they are documented here as the broader, contemporaneous threat landscape in which this PSA sits. Separately, the tactic of impersonating officials to lure prominent individuals (journalists, NGO staff, government-adjacent researchers) into an account-linking action on a commercial messaging app has a well-documented precedent in the Russian FSB-linked actor Star Blizzard (aka COLDRIVER/Callisto Group/SEABORGIUM), which CISA/NCSC (advisory AA23-341A) and subsequent reporting describe using WhatsApp-group invitations and QR-code account-linking against similar victim profiles — a TTP overlap worth tracking, but again not an attribution the FBI has made for this specific campaign.
Defensively, the core control gap this PSA highlights is that identity providers' consent screens are, by design, legitimate-looking and hosted on the re
Target sectors: government administration, news - media
Target regions: united states of america
Timeline
- CISA/NCSC jointly publish advisory AA23-341A on Star Blizzard (COLDRIVER/Callisto Group), a Russia-linked actor with a documented precedent of impersonating officials to lure journalists, NGOs, and government-adjacent researchers — a TTP overlap with PSA260901's pretext pattern, though not attributed to it.
- Star Blizzard reported compromising victims' WhatsApp accounts via QR-code account-linking after impersonating U.S. officials in invitations to Ukraine-support groups, establishing a documented precedent for messaging-app-delivered impersonation lures against high-profile targets.
- Independent reporting (BleepingComputer, Infosecurity Magazine) marks a sharp increase in OAuth device-code phishing activity against Microsoft 365 accounts beginning around September 2025, involving the financially-motivated group TA2723 and the Russia-aligned UNK_AcademicFlare.
- FBI/IC3 PSA260901 states the OAuth consent-phishing campaign against prominent individuals, their family members, and acquaintances began in this approximate period ('since late 2025').
- A concurrent OAuth device-code phishing campaign using a fake 'Salary Bonus + Employer Benefit Reports 25' document lure is detected, illustrating the same OAuth-consent-abuse technique family active in the same window as PSA260901's reporting period.
- BleepingComputer and Infosecurity Magazine publish reporting on the OAuth device-code phishing wave (SquarePhish, Graphish kits; TA2723, UNK_AcademicFlare), documenting the broader technique landscape surrounding consent phishing.
- FBI's Internet Crime Complaint Center (IC3) issues Public Service Announcement PSA260901, formally warning of the OAuth consent-phishing campaign targeting prominent, high-profile individuals via commercial messaging applications.
- CyberScoop publishes coverage of the FBI/IC3 warning, adding detail on the impersonation pretexts (draft-article review, identity verification) used to solicit OAuth consent.
Detections & IOCs
As of 2026-09-03, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 9 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, HIGH, threat intelligence, cybersecurity, T1588.002, T1585.001, T1566.002, T1684.001, T1204.001, T1098.001, T1098.001, T1550.001, T1528, T1114.002