New phishing trick gives hackers persistent access to your account, FBI warns
Hackers aren’t interested in your password, only your consent.

Photo by Annette Riedl/picture alliance via Getty Images.
- Hackers use 0Auth consent phishing to gain account access without stealing passwords or bypassing MFA.
- Victims grant access by clicking Allow on a legitimate Google or Microsoft permission screen.
- Changing a password does not remove the attacker’s access once the malicious app is approved.
- The FBI advises verifying senders and granting permissions only to trusted applications.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Hackers have been using a new social engineering technique called “0Auth consent phishing,” which grants them persistent access to your account when successful.
According to the FBI’s latest public service announcement, malicious threat actors have been targeting prominent victims, their family members, and personal acquaintances by directly sending messages containing a link to an allegedly important document.
Instead of installing spyware or other malware, the attackers gain permanent access to their victim’s account without needing to enter a password or use multi-factor authentication (MFA).
This technique, also known as “0Auth consent phishing,” has been used since late 2025. This is how it works.
A threat actor creates a malicious application and registers it with a legitimate 0Auth provider or certificate authority (CA). The app is programmed to obtain as many permissions as possible, such as reading and writing files or emails.
The attacker, often impersonating a journalist, academic, or renowned organization, then sends a message to their target containing a malicious URL redirecting to a specific file.
Once the victim clicks this link, they’re sent to a legitimate communication provider’s permission request screen, such as Google’s or Microsoft’s, and are asked to authenticate with their credentials.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
If they click “Allow,” the victim grants high-level access to the malicious application controlled by the threat actor. The hacker can then send emails or access sensitive data without ever needing to enter a password or use MFA.
What makes “0Auth consent phishing” so dangerous is that a threat actor has persistent access to his victim’s account. Changing the password doesn’t revoke the attacker’s access.
The only way to permanently cut off the hacker’s access to a compromised account is by invalidating the access token in the application’s security settings.
The FBI advises people to be vigilant about messages and communications from unknown phone numbers, accounts, or contacts not on a known contact list. The agency also recommends verifying the sender’s identity independently and granting access only to trusted applications.