Oauth phishing bypasses passwords and MFA
The FBI warns of highly targeted OAuth consent phishing attacks aimed at prominent figures, their families, and acquaintances.
Attackers impersonate government officials, media personnel, or known contacts, luring victims with fake file shares or meeting invitations.
Granting permission to a malicious OAuth application gives attackers long-term access to emails, files, and other sensitive account data.
Because this method bypasses traditional security measures, changing your password or using MFA will not stop the attack; access only ends when the app’s permission is actively revoked.
It is strongly advised to independently verify senders, avoid clicking unknown links, and regularly audit which third-party apps have access to your accounts.
Read ic3.gov article for more information.

