
No matter how many security measures you take, you can never completely protect your online footprint. Threat actors continue to find new ways to access private and personal information. In the latest incident, hackers have reportedly found a way to access your data, read your messages, and even send emails to your contacts. All this without needing your password or login details. FBI warns that OAuth phishing attack tricks victims into granting malicious apps access through legitimate Google and Microsoft permission screens.
OAuth phishing attacks are targeting Google and Microsoft accounts
Hackers just need a single click from you on a well-known platform. Once approved, these phishing attacks can give hackers access to account data without ever needing the user’s password. The technique, OAuth consent phishing, has been around for more than a year. Earlier this week, the law enforcement agency issued a new public service announcement via its Internet Crime Complaint Center (IC3), warning Americans about the threat.
OAuth (Open Authorization) is an internet standard that lets apps access your account on another service without needing your password. In simple terms, when you allow apps access to your email, Google gives it a special access token that lets it access your Google account without seeing your password.
Changing the password won’t fix it
To carry out an OAuth attack, hackers first get a malicious app registered with services like Google or Microsoft. They then contact victims through messages, pretending to be officials or media outlets, or other well-known people, and send a link to what looks like a legitimate document. This redirects the victims to a legitimate service, like Google, where they are asked to grant permissions to the malicious app.
If they approve, the attackers can access their email account and potentially do almost anything with it. What makes this worse is that simply changing the password won’t fix the problem. The only way out of this threat is to revoke the access token. You’ll have to do it through the app’s security settings.
The FBI did not reveal who the threat actors were or who they were targeting. It did say that they were “prominent victims.” They are also targeting family members as well.
The post Hackers Are Using Fake Permission Requests to Get Into Your Accounts appeared first on Android Headlines.