They Didn't Steal the Password. They Didn't Bypass MFA. The Employee Clicked "Allow."


FBI Advisory
Identity & Access
October 2026  ·  6 min read

The employee logged in to the real account. The password was correct. Multi-factor authentication worked exactly as designed. No malware touched the machine. And the attacker still walked away with access to the inbox. The mistake came one screen later.


You check the visitor's ID at the front desk. It's real. You verify it twice. It's still real.

Then you hand them a key to a specific filing cabinet, because they asked politely and the request looked routine.

The ID check was never the problem. The key was.

That's the shape of a technique the FBI issued a public warning about in September 2026: OAuth consent phishing. It doesn't need a stolen password. It doesn't need to defeat multi-factor authentication. It asks the user to do something that looks, and often is, completely ordinary: approve an app's request for permission.

Every step up to the mistake is legitimate

This is what makes the technique hard to catch with the tools most small businesses already rely on. There's no fake login page to spot, no misspelled domain, no suspicious sign-in alert to flag. The user is interacting with the real identity provider the entire time.

1
The employee logs in normally. Real username, real password, on the real sign-in page.
2
MFA happens, and it works. The second factor is checked and passed exactly as it's supposed to be.
3
A permission screen appears. An app asks to read email, access files, or view calendar and contacts. It can be framed as part of a meeting invite, a document-sharing link, or a routine sign-in prompt.
4
The employee clicks "Allow." This single click is the entire attack. Nothing else needs to go wrong.
5
The attacker receives a token, not a password. That token can stay valid for weeks or months, and it survives a password reset, because it was never tied to the password in the first place.
MFA cannot block this. MFA already happened. This is the system working exactly as designed, pointed somewhere it shouldn't go.

The FBI's September 3, 2026 public service announcement described attackers impersonating officials, media contacts, or known individuals over ordinary messaging apps specifically to get a target to approve one of these requests. No exotic infrastructure. No zero-day. Just a believable ask and a familiar-looking screen.

This is also why a password reset, usually the first instinct after a suspected compromise, doesn't fix it here. The access token the attacker holds isn't the password. It has to be found and revoked separately, in the application's own permissions or security settings, or it keeps working.

The same trust gap shows up in two other places

OAuth consent is one way attackers are learning to work around a login, rather than through it. Security researchers have flagged at least two more, worth knowing about even though this post centers on the consent-click pattern:

Recovery Rather than attacking MFA directly, attackers target the help desk or automated process that can reset or re-enroll it BleepingComputer, Sept 2026
Sessions An already-authenticated session can be stolen or preserved after login, skipping the need to re-authenticate at all Established industry pattern
Consent The subject of this post: a single approved permission request hands over durable, password-independent access FBI/IC3 PSA, Sept 2026

None of these three require breaking the login. A well-documented 2025 incident showed the scale this can reach: a single compromised third-party integration let unauthorized access spread across several hundred connected organizational accounts, entirely through legitimate, previously-granted tokens, no fresh phishing required against any of them.

The SMB translation: what to actually check this week

Most small businesses have never looked at the list of third-party apps with standing permission to their email or files. There usually isn't a monthly review process for it, because until recently there wasn't an obvious reason to think of it as a risk surface at all.

1

Review which third-party apps currently have permission to your business email or files.

Most cloud platforms have an admin page listing every app with granted access. If nobody on your team has looked at it, that's the starting point.

2

Revoke anything nobody can explain.

An unrecognized app with mail or file access isn't automatically malicious, but if nobody remembers approving it or can say why it needs that access, revoke it and ask questions after.

3

Train the specific click, not just "phishing" in general.

Most phishing training focuses on fake login pages. Add the permission-approval screen as its own category, since it looks nothing like the threat employees have been taught to recognize.

4

Confirm your help desk or IT provider verifies identity before resetting an MFA factor.

If a phone call or a chat message alone is enough to get a second factor reset, that process is a second path around MFA, independent of the one this post focuses on.

For years, the advice was protect the password, then add MFA. Both are still essential, and neither is complete anymore. The CyberScore's approach reflects that shift, looking beyond login defenses to the permissions, sessions, and recovery paths that sit just past the login screen, because that's increasingly where attackers are choosing to work instead.

The short version

Attackers are moving one step sideways, past the login instead of through it. The password held. MFA held. The business was compromised anyway, in the moment an authenticated, legitimate user decided what to allow next. That decision point, not the login screen, is where SMB defenses increasingly need to extend.

Know which third-party apps actually have access to your business data right now.

View the Threat Intelligence feed → Find Out More About ThreatAngel →
TA
ThreatAngel Team AI-powered cyber risk clarity for SMBs  ·  threatangel.com

Comments

Popular posts from this blog

The Hidden Cost of Cybersecurity Inaction for Small Businesses

Small Business Ransomware Protection Guide (2026 Edition)

Your Biggest Cyber Risk Isn't Outside Your Firewall. It's on Your Payroll.