Google, Microsoft, one click and your MFA is toast
The FBI is warning. One click on a real Google or Microsoft screen, and a stranger owns your inbox. Your password and your MFA can't help.
The facts
The FBI just rang the alarm. Its cybercrime complaint center, the IC3 (Internet Crime Complaint Center), published a warning on September 1st about an attack that breaks nothing at all. It gets you to open the door yourself.
The mechanism is called OAuth consent phishing, the protocol behind the “Sign in with Google” button and the permissions you grant to apps. You’ve clicked it a hundred times. That’s where it plays out.
Here is how it works. A stranger reaches out, by message or by email. He poses as a journalist, an academic, a public official. He sends you a link to what looks like a file-sharing service. You click. And there, you land on a real Google or Microsoft screen. Not a fake. The real one. The one asking you to authorize an app to read your inbox and your files. You approve, like always.
And it’s over for you.
The app that just received the keys belongs to the attacker. It did not steal your password. It does not need to. It holds an access token, a pass that Google or Microsoft handed it because you said yes.
And your two-factor authentication? Out of the game. MFA (Multi-Factor Authentication), that code or notification that checks it is really you, is there to control a login. Except here, nobody logs in. The attacker does not break through your door, you opened it for him. The second lock is useless when you hand over the keyring yourself.
Worse, changing your password does nothing. The token survives. To cut off the access, you have to go revoke it by hand in your account’s security settings. Until you do, the stranger stays in your house.
Two clarifications, because Mac Souverain does not deal in panic. The attack has been running since late 2025 and for now targets prominent people, their relatives, their inner circle. The FBI named neither the culprits nor the victims. But the door they push is the same one on your account as on theirs.
Why it matters to you
Ask yourself a simple question. How many things are hooked to your Google or Microsoft account?
Your inbox. Your files. Your photos. Your calendar. Your contacts. And above all, that “Sign in with Google” button you have used on thirty other sites. Your Google account is not just an account. It is the master key to your entire digital life.
That is where the real problem is. Not a hack. Google was not hacked, and neither was Microsoft. The hole is that they sell you this security as a vault when it is cardboard: a consent screen that hands out keys far too easily, and a token that laughs at your MFA.
Handing your identity and your security to Google and Microsoft means letting them manage the keyring to your whole house. The day you hand a key to the wrong guy, and that happens in one click, you do not lose a room. You lose the house.
For security, this model is junk. A single point of failure, a single click, and everything collapses. Google and Microsoft sold you the comfort of one account. They forgot to mention that one account is also one target.
The real fix is not to flee to another giant. It is to stop piling your whole life behind a single door, and to take back control over who holds your keys.
If you care about your privacy and you are reading this site, then it is probably already underway. If not, you can always start there.
What you do now
1. Before you authorize an app, read what it is asking for. “Read and manage your mail,” “access all your files,” that has no business in a simple file share. If the request goes beyond the service, close the tab.
2. Clean house, now. Go into your account’s security settings and look at the list of third-party apps with access, at Google, at Microsoft, at Apple. Anything you do not recognize, or no longer use, you remove.
3. A file-sharing link that shows up from a stranger, you do not click. Verify the sender’s identity through another channel before anything else.
4. If you have the slightest doubt about an access, revoke the tokens. Changing your password is not enough, you have to cut off the apps’ access in your account’s security settings.
Sources
- Help Net Security, cybersecurity outlet, first to surface the alert (09/02)
- FBI IC3 alert (PSA260901, ref. I-090126-PSA), September 1st 2026, primary source
- Cybernews, follow-up with the list of targets