Skip to content
Residential technology help and small-business ITOwner-led. Clearly scoped. Salem County based. 609-202-2208
Cyber News

Approving a Malicious App Can Give Account Access Without a Password

The FBI says deceptive messages can lead people to approve apps that read email or other account data. Check app permissions after an unexpected request.

Published September 1, 2026 Updated September 1, 2026 5 min read
Approving a Malicious App Can Give Account Access Without a Password

The FBI says deceptive messages can lead people to approve apps that read email or other account data. Check app permissions after an unexpected request.

What to know

  • The IC3 says targeted people received direct messages or email that appeared to come from government officials, media figures, publicly known personalities, or event coordinators.
  • The link may be presented as a file-sharing service, an event invitation, or an identity check.
  • Approving the wrong app can allow it to act on the user’s behalf, including reading and sending email or accessing sensitive data.
  • The IC3 says this access may continue after a password change and must be removed by invalidating the app’s permission in the account’s application security settings.

Why an app approval can matter

People who receive email or direct messages could encounter this type of scam. The IC3 says that since late 2025, cyber actors have targeted prominent people, their family members, and personal acquaintances with malicious links.

The message may impersonate a government official, media figure, publicly known personality, or event coordinator. Its link may instead be presented as a file-sharing service, an event invitation, or an identity check.

OAuth is a standard way for one website or app to request access to an account on another service without asking the user to share the account password. In consent phishing, a deceptive message leads to an app permission screen and persuades the user to approve access.

The IC3 says the permission screen may belong to a legitimate communication provider. If the user approves the request, the malicious app may act on the user’s behalf. It may read and send email or access sensitive data.

The alert says this technique can bypass passwords and multi-factor authentication, which is an extra sign-in check. The access can persist until the victim revokes the app’s permission; changing the password alone may not remove it.

What to do before or after a request

Before approving access, examine unexpected messages from unfamiliar phone numbers or accounts, or messages outside your known contacts. Verify the sender through a separate method, such as a known phone number or a new message thread. Only authorize an app you trust and expected to use.

If you approved an app by mistake, open the affected account’s application or security settings. Look for connected apps or permissions you do not recognize and revoke the suspicious permission. Account menus differ, so use the service’s own help pages if needed.

Do not use the unexpected message’s link to investigate the request, and do not assume that changing your password removed the app’s access. The IC3 asks people who believe they were victims to contact relevant security officials, report to a local FBI field office or IC3, and keep screenshots of the messages.

Does this affect me?

Who may be affected
People who receive email or direct messages should care about this technique. The alert describes a scam method involving OAuth authorization rather than naming a flaw in a specific product.
How to check
Review the connected-app or application-permission settings for an account where you may have approved an unexpected request.
What to do
If you find an app you do not recognize, revoke its permission in the account’s application security settings.
What to avoid
Do not approve an app from an unexpected message, even if the permission page looks familiar. Do not rely on changing your password alone to remove existing app access.

Common questions

Can this scam work if I use multi-factor authentication?

The IC3 says it can. The request is for permission to an app rather than only for a password, and the alert says this technique can bypass passwords and multi-factor authentication.

Will changing my password remove the app’s access?

Not necessarily. The IC3 says access granted through this technique can remain until the victim invalidates the app’s permission in the application security settings. Review connected apps and revoke anything suspicious.

What should I do if I clicked the link but did not approve the app?

Do not continue with the request or enter information. Check the account’s connected-app settings for an unfamiliar permission. If you believe you were affected, keep screenshots and report the matter to IC3 or a local FBI field office.

Primary source

This article is based on the FBI Internet Crime Complaint Center (IC3) alert “Malicious Cyber Actors Gain Access to Victim Accounts Through Consent Phishing,” published September 1, 2026: https://www.ic3.gov/PSA/2026/PSA260901. See the original alert for full reporting instructions and technical details. Read the complete original source.

Get the important updates without the noise

Choose the devices and topics you care about in Cyber Alerts.

Choose my alerts

Article history: Published Sep 1, 2026 at 10:50 am EDT. Updates and corrections are noted here when material facts change.