The FBI is warning that hackers have found a way into personal accounts that never steals your password and walks right past multi-factor authentication.

The alert landed September 1, 2026, as advisory I-090126-PSA. It describes OAuth consent phishing, run since late 2025 against prominent victims, their family members, and acquaintances.
The attacker keeps the access you approved, and resetting your login does nothing to kick them out.
How OAuth Consent Phishing Works
OAuth lets one app reach your account on another service without ever seeing your login. You have approved it dozens of times already.

Criminals build an app, register it with a real provider, and set it to request heavy permissions: reading your files, sending mail from your inbox.
Then comes the message. Criminals pose as government officials, journalists, and event coordinators, sending a link to a shared file or identity check.
Click through and you land on a real Google or Microsoft permission screen. Not a counterfeit. Signing in legitimately does not make the request behind it safe.
Approve it and a stranger can act as you. The bureau put it plainly:
Hide Your Digital Fingerprint
‘By registering malicious applications through legitimate authorization protocols and using social engineering tactics, cyber actors can bypass both passwords and multi-factor authentication, which makes consent phishing especially dangerous.’

Why Changing Your Password Will Not Save You
Most breach advice assumes a stolen credential is the problem. Reset it, turn on two-factor, move on.
That advice fails here. The app holds an access token, a separate key issued when you approved it, so a new password leaves the intruder in place.
Revoking that app in your account security settings ends its access, usually under connected apps or third-party access. Check your sent mail and forwarding rules afterward.
I have watched cord-cutters get burned by fake login pages for years, and this raises the bar. The counterfeit is gone, because the provider really did serve that permission screen.
Plenty of us sign into live TV services with a Google account, and some exchange messages with an unfamiliar IPTV seller. The bureau has not observed it aimed at streamers, though I expect the trick to drift into the streaming scams we already cover.
Final Thoughts from Troy
An attack that survives a password reset should stop you cold, because it breaks the one step most people take after a scare. Treat links from unfamiliar numbers and accounts as hostile, confirm the sender through a channel you already trust, and approve only apps you know.
For more details on this story, refer to the official FBI public service announcement and the report from Cybernews.
We want to know your thoughts. What do you think about this story? Let us know in the comment section below!
Be sure to stay up-to-date with the latest streaming news, reviews, tips, and more by following the TROYPOINT Advisor with updates weekly.
Exclusive Surfshark Discount
Your online activity is currently monitored by your ISP, app/addon/IPTV developers, government agencies, and the websites you visit.
- Become 100% anonymous while streaming and downloading.
- Use on Unlimited Devices & share 1 account with the entire family.
- Save 85% with the 24-Month Plan + Get 3 FREE Months.
This page includes affiliate links where TROYPOINT may receive a commission at no extra cost to you. Many times, visitors will receive a discount due to the special arrangements made for our fans. Learn more on my Affiliate Disclaimer page.





