Federal authorities have issued a new warning about a sophisticated online scheme that lets criminals quietly seize control of email and cloud accounts without ever stealing a password. The alert, released through the FBI’s Internet Crime Complaint Center on September 1, 2026, describes an operation that has been active since late 2025 and focuses on well-known individuals, their relatives, and people in their personal circles.
Attackers typically begin by sending private messages on popular commercial messaging platforms.
They pose as government officials, journalists, or other recognizable public figures and urge the recipient to open a link that supposedly leads to a shared document or file-sharing service.
In earlier versions of the same campaign, the same operators impersonated event organizers and asked targets to “verify identity” before attending a gathering.
Once the link is clicked, the victim is taken to a genuine permission screen belonging to a major email or cloud provider.
Approving that request hands a malicious application—registered through legitimate authorization channels—broad, lasting access to the account.
What makes the method especially dangerous is its persistence.
Unlike traditional phishing that harvests usernames and passwords, this approach grants a token that remains valid even after the victim changes credentials or enables extra authentication steps.
The only way to cut off the attacker is for the account owner to locate and revoke the unauthorized application inside their security settings.
Until that happens, the criminal can read incoming mail, send messages that appear to come from the victim, and rummage through stored files.
The FBI notes that the tactic exploits the same authorization framework everyday apps use to request limited access.
Because the permission screen itself is authentic, many users do not hesitate to click “Allow.”
Combined with social-engineering pressure from an apparently trusted sender, the ruse can slip past both passwords and multi-factor authentication.
Officials recommend treating unexpected messages from unknown numbers or accounts with extra caution.
Recipients should independently confirm the sender’s identity through a separate, trusted channel before following any link or granting any application permission.
Only well-known, verified services should ever be authorized.
Anyone who suspects they have already approved a fraudulent request is urged to review their connected apps immediately, revoke suspicious entries, and notify both their organization’s security team and the FBI.
Reports can be filed with a local field office or through the Internet Crime Complaint Center at ic3.gov; screenshots of the original messages should be preserved.
The campaign illustrates how criminals continue to adapt as users grow more wary of fake login pages. By hiding behind a real authorization process, they convert a single moment of trust into long-term account control. Heightened vigilance when granting third-party access remains the most practical defense.