The FBI has flagged a phishing technique that steals account access without ever collecting a password, then keeps the door open even after credentials change. Attackers register a malicious application with a legitimate cloud provider and persuade targets to approve it, so the victim’s own permission screen hands over email, contacts, and other data.
Since late 2025 the bureau has watched the approach used against prominent individuals and their circles, often through a commercial messaging app where the attacker poses as a public figure or official. Targets are invited to verify their identity with a seemingly legitimate app, and clicking Allow on a genuine Microsoft 365 or Google prompt grants broad rights. The token does not expire when the account password changes, so access survives until the malicious app is removed from the account’s security settings.
Healthcare organizations lean heavily on the same cloud platforms, and hospital IT teams have watched phishing evolve from credential theft toward authorization abuse that defeats multifactor authentication. The FBI’s advice: treat unsolicited messages from unknown numbers and senders with suspicion, verify identities outside the conversation, approve only trusted applications, and audit the permissions those apps hold. Removing unrecognized apps belongs in account-recovery playbooks alongside password resets.