
There is a new scam that the FBI is warning the public about as it could give hackers complete access to your email.
The cyber attack is reportedly done through consent phishing and could mean that scammers gain access to your emails even after you’ve changed your password.
This comes after the FBI released a warning to alert people to a new scam technique known as ‘OAuth consent phishing’.
According to the agency, since late last year, ‘malicious cyber actors have been targeting prominent victims, their family members, and personal acquaintances by directly messaging personal accounts with malicious links’.
Advert
The FBI continued: “Recently observed activity includes impersonating government officials, media, and other publicly known personalities on a commercial messaging application (CMA) and soliciting the targeted individual to access a malicious link under the guise of a file sharing service through an application under the malicious actor's control.

“Previous phishing campaigns have also impersonated event coordinators and planners, who sent malicious links to targets under the guise of an invitation to an event and the need to verify the target's identity through a malicious application under the actor's control.”
How does OAuth consent phishing work?
This type of cyber attack is different to spear phishing, which relies on links, access to ‘malicious credential harvesting sites or malware deployment’ in order to gain access to certain email accounts.
Instead, OAuth consent phishing allows a hacker to have access to emails even if a password is reset and can only be removed if the account holder invalidates the token in their application security settings.
Often, the OAuth will appear to be from a legitimate company including the likes of Google or Microsoft, which makes the victim believe they are signing into their email.
From there, the user will receive an email urging them to click a link, often appearing like a verification link.

However, instead of verifying their email, what the single click actually does is give the hacker unauthorized access to their private information in their email account.
How to protect your email account from hackers
There are ways to improve your cybersecurity, with the FBI recommending to deploy ‘mitigation strategies’ including practising increased scrutiny of communications from unfamiliar phone numbers or anyone who isn’t in your known contact list.
It is also important to verify the identity of senders before engaging with an email and only ‘grant authorization to trusted applications’.