FBI Warning:  A New Phishing Scam That Doesn’t Need Your Password

Just when you thought you had phishing scams figured out, the bad guys found another way in.

The FBI issued a warning this week about a growing cyber scam called “consent phishing.”

That name sounds complicated. The scam really isn’t.

Instead of tricking you into giving away your password, criminals trick you into giving them permission to access your account.

And here’s what makes this one particularly nasty: the page asking for permission may actually be a legitimate Google, Microsoft or other familiar login page.

Here’s how it works

You get an email, text or direct message that appears to come from someone legitimate.

Maybe it’s supposedly a government official.

Maybe a reporter.

Maybe an event planner sending you an invitation.

Maybe someone wants you to look at a document or photograph.

The message includes a link.

You click it.

You may then be taken to a perfectly legitimate-looking login page and asked to sign into your Google, Microsoft or another account.

So far, nothing necessarily looks suspicious.

Then comes the important part.

A box pops up asking you to give an application permission to do certain things.

Read your email.

Access your files.

Send email on your behalf.

And you click:

ALLOW.

Congratulations.

You may have just handed a criminal the keys to your digital house.

The FBI says criminals are using malicious applications connected through a legitimate authorization system known as OAuth. Once permission is granted, the criminal’s application can potentially read emails, access files, obtain sensitive information and even act on the victim’s behalf.

“But I have two-factor authentication!”

Good.

Keep it.

But here’s the disturbing part about this scam.

The FBI warns that this particular attack can bypass the protections people normally rely upon—including passwords and multi-factor authentication—because you authorized the application yourself.

In other words, the criminal didn’t break down your front door.

He rang the doorbell.

And somebody opened the door and invited him inside.

Changing your password may not fix it

This may be the most important thing to understand.

Normally, if we think an account has been compromised, the first thing we do is change the password.

With this scam, that may not be enough.

Once you give the malicious application permission, it can receive what’s essentially a digital authorization token allowing continued access.

The FBI says that access can remain even after the victim changes the account password. The malicious application must be removed or its authorization revoked through the account’s security settings.

So what should you do?

The easiest rule may be this:

Stop clicking “Allow” unless you know exactly what you’re allowing.

If an unexpected email or message asks you to open a document, verify your identity or connect an application to your Google, Microsoft or another important account, don’t assume it’s legitimate simply because the login screen looks legitimate.

Contact the sender another way and ask:

“Did you really send this to me?”

And when one of those permission screens appears, actually read it.

If some application you’ve never heard of wants permission to read your email, access your files or act on your behalf, that’s a pretty good moment to hit CANCEL, not ALLOW.

The FBI also recommends being especially cautious about messages coming from unfamiliar numbers or accounts and independently verifying who sent them.

Already clicked “Allow”?

Don’t just change your password and assume you’re safe.

Go into the security settings for the affected account and review the applications and services that have permission to access it. Revoke access for anything you don’t recognize or no longer use.

If you believe you’ve been victimized, preserve screenshots and messages and report the incident to the FBI’s Internet Crime Complaint Center at IC3.gov.

And perhaps send this article to your parents, children, employees and friends.

Because the next generation of phishing isn’t always asking:

“What’s your password?”

Sometimes it’s simply asking:

“Will you let me in?”

And unfortunately, one little click can answer yes.

admin

Eye’s team is having a doggone good time keeping you informed of the issues of the day. Send us your stories and we’ll sniff them out!

Comments

Post Your Comment

Your email address will not be published. Required fields are marked *