FRAUD CHECK — Squire It™
sharelivefraud.com/squire-it
LIVE FRAUD ALERT
LIVEFRAUD Check #66
FBI WARNS

A published FBI/IC3 public service announcement describes "OAuth consent phishing": attackers direct-message people with a malicious link that leads to a real permission screen, and approving it hands a hostile app ongoing access to the account without any password.

HIGH CONFIDENCEPublished 2026-09-04
S
Q
U
I
R
E
D
E
S
K
·
C
H
E
C
K
E
D
·
B
A
T
T
L
E
D
·
R
E
C
E
I
P
T
E
D
·
S

What we found

An IC3 public service announcement dated 1 September 2026 states that since late 2025 malicious cyber actors have been directly messaging the personal accounts of prominent people, their family members and personal acquaintances with malicious links, using a technique it calls "OAuth consent phishing". The announcement says recently observed activity includes impersonating government officials, media and other publicly known personalities on a commercial messaging application, and inviting the target to open a link disguised as a file sharing service run by an application under the actor's control. It adds that earlier campaigns impersonated event coordinators and planners, sending links framed as an event invitation that required the target to confirm their identity through the actor's application. According to the announcement, clicking the link redirects the user to a genuine communication provider permission request screen, and approving that request grants high-level access to the attacker's application, letting the actor read and send email and reach sensitive data on the user's behalf without ever holding the password. The announcement states this access can only be removed by the victim invalidating the token in their application security settings — changing the password does not end it — and that registering malicious applications through legitimate authorization protocols lets actors bypass both passwords and multi-factor authentication. If a message you did not expect sends you to a screen asking you to approve access for an app, close it without approving, then open your account's app permissions page yourself and remove anything you do not recognise. The harvested announcement does not name the commercial messaging application involved, does not name the malicious applications or any impersonated individual, and gives no count of people affected or of money lost. LIVEFRAUD ALERTS is independent and is not affiliated with any agency, company or platform named here; this alert was written only from the harvested material cited above.
THE RULE
One approval tap on a real-looking permission screen can hand a stranger ongoing read-and-send access to your mailbox, and changing your password will not shut it off.

What we don’t know

The bench — who voted

4 INDEPENDENT AI MODELS REVIEWED THIS. ALL 4: HIGH RISK.

The card names a count. Here are the seats behind it, with what each one said.

ANTHROPICclaude-opus-5 · HIGH
The single evidence row supports only the skeleton: an IC3 PSA of 1 September 2026, direct messages with links, a legitimate permission screen, high-level access to a malicious app, survival of a password change and bypass of MFA. The finding adds a large body of specifics found nowhere in the row — the 'since late 2025' start date, impersonation of government officials, media figures and publicly known personalities, the file-sharing-service disguise, the earlier event-coordinator/invitation campaigns requiring identity confirmation, and the label 'OAuth consent phishing' itself. These are presented as direct paraphrase of the announcement but are not attested by the evidence provided.
DISSENT, PRESERVEDJudged separately from the sourcing problem, the pattern is genuinely dangerous and I would grade it high. Consent phishing defeats the two defences most readers have been trained to rely on — changing the password and enabling MFA — and leaves a durable token that an ordinary user will not think to look for. The permission screen is authentic, so every visual trust signal a reader is taught to check will pass.
DISSENT, PRESERVEDThe remediation advice given — close the screen, then navigate independently to your account's app permissions page and revoke anything unrecognised — is correct and useful regardless of whether the narrative detail is sourced. If the panel trims this alert, that instruction should survive.
DISSENT, PRESERVEDThe correct fix here is subtraction, not retraction: strip the unattested campaign detail and the token-revocation mechanism, keep the mechanism-plus-advice core, and the piece would hold at high confidence.
GOOGLEgemini-flash-latest · HIGH
The finding includes numerous specific factual details that do not appear anywhere in the provided evidence row, such as the timeframe ('since late 2025'), the term 'OAuth consent phishing', specific lures (impersonating government officials, media figures, and event planners), specific pretexts (file-sharing services and event invites), and specific impacts (reading and sending email, invalidating tokens in security settings).
GROQopenai/gpt-oss-120b · HIGH
The finding adds specifics (impersonation of officials, media, event coordinators, disguised file‑sharing links, timeline since late 2025, etc.) that are not present in the sole evidence row, which only confirms the existence of OAuth‑consent phishing and that approval grants high‑level access persisting beyond password changes.
OPENROUTERopenrouter/free · HIGH
Raised no objection; read the evidence as holds.

Reviewed by 4 independent models: 1 found it carried by the evidence, 3 did not.

▼ Protocol & challenge record
Objection (medium): Vector narrowing in the headline claim. The claim states flatly that "attackers direct-message people with a malicious link." The source says the attack "typically begins with a phishing email OR direct message through a CMA." The DM channel is what was 'recently observed', but by dropping email the claim gives readers a false negative filter — someone who receives the same consent lure by email may conclude the alert does not apply. The finding body inherits this: every lure sentence is DM-framed, and the source's email vector never appears.
Not resolved — preserved on the record.
Objection (medium): Unattributed absolute in the risk_line. "...changing your password will not shut it off" is asserted in LIVEFRAUD's own voice as a general truth about accounts. The source only asserts it about this technique, and the real-world behaviour is provider-dependent (several major identity providers do revoke or force re-consent on OAuth refresh tokens after a credential reset or session revocation). Everywhere else the draft is careful to write "The announcement states..."; the risk_line drops that hedge at exactly the point where a reader might skip the token-revocation step because they were told password changes are futile in general. Keep the substance, restore the attribution or scope it to "according to the FBI".
Not resolved — preserved on the record.
Objection (medium): Two directive_options are broken output, not English: "Send this to any multi-factor you know" and "Forward this to the multi-factors in your life." These read as a template that substituted a technical term into a person slot. They are half of the offered directive set, so a re-roll or downstream selection could ship one. A third, "Send this to any coordinator you know," is misdirected — event coordinators in this source are the impersonated party, not the targeted party; telling coordinators to watch out inverts the threat model.
Not resolved — preserved on the record.
Objection (low): Naming stretch: "using a technique it calls 'OAuth consent phishing'" implies the agency coined or is the authority for the label. The source says "a technique known as 'OAuth consent phishing'" — it is citing an existing industry term. Minor, but it slightly inflates the source's role.
Resolved: Reworded in place: change "using a technique it calls" to "using what it describes as a known technique, 'OAuth consent phishing'". No sourcing change required.
Objection (low): Attribution label "FBI/IC3" in the claim is one inferential step past the harvested text. The row is an ic3.gov PSA and refers to the FBI in the third person ("The FBI requests victims also report..."). IC3 is FBI-operated so this resolves, but the harvested text never says "the FBI issued this announcement." The finding's own wording ("An IC3 public service announcement") is the safer form and should have been used in the claim too.
Resolved: Align the claim to the finding's wording — "An IC3 (FBI Internet Crime Complaint Center) public service announcement" — which is exact and still gives readers the FBI signal.
Objection (low): Callout/icon fit. "ATTENTION: PARENTS" in callout_options has no anchor in the source — the targeting is prominent people, their family and acquaintances, which is not the same population. The "text-message" watch icon asserts SMS when the source says only "a commercial messaging application" and the finding explicitly flags that the app is unnamed; the icon quietly resolves an unknown the prose preserves.
Resolved: Drop "ATTENTION: PARENTS" from callout_options; drop the text-message icon or replace with a generic message/chat icon, since the finding's own limitation line says the messaging app is unnamed.
Objection (low): The draft omits the source's own mitigation guidance (scrutinise messages from unfamiliar numbers/accounts, independently verify the sender's identity, grant authorization only to trusted applications) and substitutes an unsourced advice line. The substituted advice is defensible and follows from the token-revocation statement, but dropping the official tips in favour of house advice is a needless loss of sourced, quotable protective content.
Not resolved — preserved on the record.
Objection (medium): Date currency cannot be self-verified from the packet. The row is dated 2026-09-01T14:00:00Z with slug PSA260901. If the run date is earlier than 1 September 2026, this row is a future-dated artefact and the whole item is unpublishable regardless of internal consistency. Nothing in the draft records the harvest date against the publication date, so this check has not been performed. It must be before publish.
Not resolved — preserved on the record.
Objection (low): "Bypass multi-factor authentication" is repeated without the nuance that consent phishing generally rides an already-authenticated session or a legitimate provider sign-in the victim completes themselves — MFA is not defeated, it is satisfied by the victim and then rendered irrelevant by the persistent grant. The draft attributes the phrase to the announcement, which is correct practice, so this is a clarity point rather than an accuracy failure — but readers may take away "MFA is useless," which is the wrong operational lesson.
Resolved: Retain the attributed quote but add half a clause noting the announcement's point is persistence of the grant, not defeat of the MFA challenge itself — or simply leave as-is, since attribution is already correct and the operational advice (revoke the app) is unaffected.
Objection (low): Confidence "high" on a single row is generous by the draft's own reasoning — the third confidence_reason concedes no corroboration on scale, victims or platform. The mechanism claims are near-verbatim so high is defensible for those; but the confidence label attaches to the item as a whole, including the targeting framing in the audience callout, which is single-sourced and unquantified.
Not resolved — preserved on the record.
Preserved dissent
ON THE RECORDI do not accept the risk_line as written. "...changing your password will not shut it off" is stated in our own voice as a general property of accounts, and it is not one — token invalidation behaviour on credential reset varies by provider, and several major providers do kill or force re-consent on OAuth grants after a password change plus session revocation. The FBI can say it because they are describing their own observed cases; we are generalising it into a rule for every reader's mailbox. The whole rest of the draft is disciplined about "the announcement states" and then the one line most likely to be screenshotted and forwarded drops the hedge. If this ships unattributed I want it recorded that I objected.
ON THE RECORDThe two directive_options reading "Send this to any multi-factor you know" and "Forward this to the multi-factors in your life" are not stylistic quibbles — they are evidence that the directive generator substituted a security term into a person-shaped slot without a sanity check. Whatever produced them will produce them again. Fixing these two strings without looking at why they were produced is not a fix.
ON THE RECORDI think confidence "high" overreaches on the targeting framing specifically. The mechanism is quoted almost verbatim and deserves high confidence. The audience callout 'PROMINENT PEOPLE AND FAMILY' rests on one undefined word in one PSA — 'prominent victims' — with no numbers, no geography and no detection method, and the announcement itself says nothing about who is not at risk. Calling that high-confidence targeting invites the alert to be read as 'not about me' by exactly the readers who use the same consent screens.

The sources

Official sourceMalicious Cyber Actors Gain Access to Victim Accounts Through Consent Phishing2026-09-01
An IC3 public service announcement dated 1 September 2026 describes actors direct-messaging prominent people, their family members and acquaintances with links that lead to a legitimate permission screen, where approval grants a malicious application high-level account access that survives a password change and bypasses multi-factor authentication.
Authority: official. Retrieved 2026-09-04.
Limitation: The announcement names no platform, no application, no impersonated individual and no victim or loss figures, and does not say how the activity was detected or over what geography.
Open the original source →

Other checks

Every check we have published →

Share this receipt
sharelivefraud.com/check/Gbqsau4

Published under standing founder pass (A9) — every claim source-mapped by the machine.

▼ What the machine checked
  • ✓ Not a community submission.
  • ✓ No entity is named.
  • ✓ All 5 material sentence(s) map to FBI/IC3.
  • ✗ anthropic returned "overstated"; google returned "overstated"; groq returned "overstated" — published on the receipt, not blocking (A9 amendment).
  • ✓ No audience band is set.

No human affirmed these. They were verified by the classifier described in Amendment A9, on 2026-09-04.

Something wrong here? Tell us and we'll correct it — corrections are published, not quietly edited.

Phishy? Send it → sharelivefraud.com/squire-it

Not affiliated with any government agency, credit bureau, bank, platform, or law-enforcement agency. Informational only — not legal or financial advice.

Naming a source is not an endorsement, and being named here is not an accusation against any company.

Powered by SquireIt™

Verify this receipt at squireit.com

Join Squire’s First Watch

Alerts before the feed. Credit when your summons becomes a receipt. A vote on what we check next. Founding names are permanent.

Get the next one

We publish a receipt for every alert, including the ones we decide not to run.

We will ask you to confirm before anything is sent. Your address is used for this and nothing else, and is never shared.