MedRisk
  • Home
  • News
    NewsShow More
    Community behavioral health clinic building exterior
    Class action probe opens over St. Louis behavioral health breach

    Attorneys opened a class action probe into Provident Behavioral Health days after…

    September 10, 2026
    Office desk with tablet face down, padlock and envelope
    Malicious app grants can bypass MFA and outlive resets, FBI warns

    The FBI warns that consent phishing grants can bypass multifactor authentication and…

    September 10, 2026
    Row of small medical office buildings in a suburban park
    Four small care providers tie breach notices to ransomware claims

    Four small care providers tied fresh breach notices to ransomware activity, with…

    September 10, 2026
    Hospital headquarters building with a padlock icon
    Pixel tracking lawsuit against Georgia system ends in $4.5M deal

    Wellstar Health System agreed to pay $4.5M to settle claims that website…

    September 10, 2026
    Bright mammography suite with technician beside the scanner
    Metaencryptor adds diagnostics maker Hologic to its extortion roster

    Metaencryptor posted women's health technology maker Hologic on its leak site on…

    September 10, 2026
  • Articles
    ArticlesShow More
    German textile firm insolvency after cyberattack highlights healthcare supply chain risk

    ZEGO-TVZ collapse after cyberattack reveals healthcare supply chain vulnerability in specialized medical…

    July 18, 2026
    CISA forensic report on AWS credential leak highlights healthcare contractor risks

    CISA analysis of May 2026 credential leak warns healthcare organizations about contractor…

    July 18, 2026
    Healthcare data breach settlements mount with ransomware and pixel tracking payouts

    Two major healthcare data breach lawsuits reached settlements this week totaling over…

    July 12, 2026
    83K exposed in email hack as LockBit 5 surfaces and healthcare breaches multiply

    Multiple healthcare data breaches were reported this week, with Aitkin County Health…

    July 12, 2026
    Study Reveals 73% of Healthcare Websites Leak Data via Hidden Tracking Tools

    A new study reveals that 73% of healthcare websites use marketing tracking…

    July 12, 2026
  • Features
    FeaturesShow More
    HIPAA security rule overhaul pushed to July 2027 as healthcare sector pushes back

    HHS has delayed the first major HIPAA Security Rule overhaul in over…

    July 12, 2026
    Healthcare Cyberattacks Persist as SonicWall Report Flags Millions of Exploitation Attempts and Rising Ransomware Pressure

    SonicWall’s latest Healthcare Protect Brief warns that healthcare remains the most persistently…

    June 23, 2026
    FTC Warns Tech Giants Against Weakening Encryption or Enabling Censorship

    The agency cautions leading U.S. tech companies that complying with foreign demands…

    May 17, 2026
    McLaren Health Care Confirms Ransomware Attack Affecting 740,000 Patients in Michigan

    The provider has disclosed a ransomware attack that compromised the personal and…

    May 17, 2026
    EU Allocates €145.5M to Boost Cybersecurity in Healthcare and SMEs, Launches Dual Funding Calls

    The European Commission is investing €145.5 million to strengthen cybersecurity across public…

    May 17, 2026
  • Spotlight
    SpotlightShow More
    Ryuk operator pleads guilty Blackcat AlphV conspirator sentenced to 6 years

    Two ransomware actors face prison time in separate cases involving Ryuk and…

    July 13, 2026
    Legacy Sitecore Flaw Exploited in Healthcare Environments to Deploy WeepSteel Malware

    Mandiant warns that outdated Sitecore configurations in healthcare systems could expose sensitive…

    May 17, 2026
    Three Healthcare Organizations Disclose Major Data Breaches Impacting Over 175,000 Patients

    Recent breaches at CPAP Medical Supplies, a Miracle Ear franchisee, and a…

    May 17, 2026
    Stealthy Prompt Injection in Images Lets Attackers Hijack AI Systems

    Researchers have discovered a method for hiding malicious instructions in images that…

    May 17, 2026
    Transparent Tribe Targets Indian Government With Malicious Desktop Shortcut Files

    The Pakistani-linked APT36 group has expanded its tactics by weaponizing Linux BOSS…

    May 17, 2026
  • About
    • Mission
    • Services
    • Contact
  • Alerts
  • AI Risk
  • Compliance & Legal
  • Cryptography
  • CVEs
  • Data Breaches
  • Malware
  • OT/ICS
  • Phishing
  • Privacy
  • Ransomware
  • Social Engineering
  • Startups
  • Threats
MedRiskMedRisk
Font ResizerAa
  • Home
  • News
  • Articles
  • Features
  • Spotlight
  • Events
Search
  • Quick Links
    • Home
    • News
    • Articles
    • Features
    • Spotlight
  • About MedRisk
    • Mission
    • Services
    • Contact
Have an existing account? Sign In
Follow US
© 2026 MedRisk. All Rights Reserved.
News

Malicious app grants can bypass MFA and outlive resets, FBI warns

The FBI warns that consent phishing grants can bypass multifactor authentication and survive password changes.

MedRisk Staff
Last updated: September 10, 2026 5:29 am
By
mradmin
Share
2 Min Read
Office desk with tablet face down, padlock and envelope
SHARE

The FBI has flagged a phishing technique that steals account access without ever collecting a password, then keeps the door open even after credentials change. Attackers register a malicious application with a legitimate cloud provider and persuade targets to approve it, so the victim’s own permission screen hands over email, contacts, and other data.

Since late 2025 the bureau has watched the approach used against prominent individuals and their circles, often through a commercial messaging app where the attacker poses as a public figure or official. Targets are invited to verify their identity with a seemingly legitimate app, and clicking Allow on a genuine Microsoft 365 or Google prompt grants broad rights. The token does not expire when the account password changes, so access survives until the malicious app is removed from the account’s security settings.

Healthcare organizations lean heavily on the same cloud platforms, and hospital IT teams have watched phishing evolve from credential theft toward authorization abuse that defeats multifactor authentication. The FBI’s advice: treat unsolicited messages from unknown numbers and senders with suspicion, verify identities outside the conversation, approve only trusted applications, and audit the permissions those apps hold. Removing unrecognized apps belongs in account-recovery playbooks alongside password resets.

TAGGED:Account TakeoverEmail SecurityFBIhealthcare ITMFAOAuthPhishing
SOURCES:The HIPAA JournalFBI Internet Crime Complaint Center
Share This Article
Email Copy Link Print
Previous Article Row of small medical office buildings in a suburban park Four small care providers tie breach notices to ransomware claims
Next Article Community behavioral health clinic building exterior Class action probe opens over St. Louis behavioral health breach

You May also Like

AlertsNews

Apple Patches Sixth Zero-Day of 2025 in ‘Extremely Sophisticated’ Image-Based Attack

May 17, 2026
AlertsNews

Coordinated Botnet Targets Microsoft RDP Web Clients in Massive Enumeration Surge

May 17, 2026
News

Healthcare still tops IBM breach cost study at $6.64M average

August 1, 2026
AlertsNews

Critical Citrix NetScaler Zero-Day Exploited in the Wild

May 17, 2026
Show More
MedRisk

The latest in healthcare & medical technology risk
From breaking news to expert analysis, our coverage helps professionals stay informed, secure, and ahead of the threat curve.

X-twitter Youtube Linkedin

© 2026 MedRisk. All rights reserved. Privacy | Legal

Quick Links

  • News
  • Articles
  • Features
  • Spotlight
  • Events
  • Mission
  • Services
  • Contact
Welcome to Foxiz
Username or Email Address
Password

Lost your password?