They Didn't Steal the Password. They Didn't Bypass MFA. The Employee Clicked "Allow."
FBI Advisory Identity & Access October 2026 · 6 min read The employee logged in to the real account. The password was correct. Multi-factor authentication worked exactly as designed. No malware touched the machine. And the attacker still walked away with access to the inbox. The mistake came one screen later. You check the visitor's ID at the front desk. It's real. You verify it twice. It's still real. Then you hand them a key to a specific filing cabinet, because they asked politely and the request looked routine. The ID check was never the problem. The key was. That's the shape of a technique the FBI issued a public warning about in September 2026: OAuth consent phishing. It doesn't need a stolen password. It doesn't need to defeat multi-factor authentication. It asks the user to do something that looks, and often is, completely ordinary: approve an app's requ...