AHA - American Hospital Association

09/09/2026 | News release | Distributed by Public on 09/09/2026 14:26

FBI warns of cyber actors deceiving individuals through ‘OAuth consent phishing’

An FBI alert released Sept. 1 warns of cyber actors impersonating government officials, media and other public individuals on a commercial messaging app to target victims by sending malicious links that leverage a technique known as "OAuth consent phishing." The technique typically involves clicking a link within a phishing email or direct message through a messaging app that directs a user to a legitimate communication provider permission request screen. If the user approves the request, they unknowingly grant high-level access to a malicious app controlled by the cyber actor. From there, the cyber actor can act on behalf of the user for actions such as reading and sending emails or accessing sensitive data - without having access to the user's credentials.

For more information on this or other cyber and risk issues, contact John Riggi, AHA national advisor for cybersecurity and risk, at [email protected], or Scott Gee, AHA deputy national advisor for cybersecurity and risk, at [email protected]. For the latest cyber and risk resources and threat intelligence, visit aha.org/cybersecurity.

AHA - American Hospital Association published this content on September 09, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on September 09, 2026 at 20:26 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]