Back to blog

Consent Forms: The FBI Says Fake Event Invitations Are Now Stealing Inboxes Without a Password

HB
Henrique B. 11 September 2026 · 5 min read
Consent Forms: The FBI Says Fake Event Invitations Are Now Stealing Inboxes Without a Password

The FBI has issued a public warning about a phishing technique that dresses itself up as an event invitation, and it does not need your password to work. In a 1 September alert, the bureau said attackers have posed as event coordinators, sent "invitations" that lead to a legitimate-looking permission screen, and walked away with persistent access to the victim's mailbox. If you send registration links for a living, this one is about you.

Consent forms: what the FBI actually said

The alert, numbered I-090126-PSA, describes a technique called OAuth consent phishing. Since late 2025, the FBI says, criminals have been targeting prominent people, their families and their acquaintances by direct-messaging malicious links, most recently while impersonating government officials, journalists and other public figures on a commercial messaging app.

The part that matters for organisers is the earlier campaign the bureau references in the same breath. Attackers impersonated event coordinators and planners, sent targets a link framed as an invitation to an event, and told them they needed to verify their identity through an application. That application belonged to the attacker.

The mechanism is what makes it nasty. OAuth is the framework behind every "sign in with Google" or "connect your Microsoft account" button on the internet. A consent-phishing link sends the victim to a real permission screen from a real provider, asks them to authorise an app with a plausible name, and, if they click Allow, hands that app the right to read and send email and rummage through files. No password changes hands. Multi-factor authentication never gets a say. And, as the FBI notes, changing your password afterwards does nothing, because the token lives on until the victim finds the app in their account security settings and revokes it.

Why event invitations make the perfect lure

Skift Meetings picked up the alert on 8 September and asked two people who deal with this for a living why events are such good bait. The answer is uncomfortable: the industry has spent twenty years training attendees to click links from people they have never met.

Mike Bushman, chief technology officer at registration vendor RainFocus, put it in terms of built-in legitimacy and urgency. Delegates expect registration links, calendar invites and speaker-portal logins from unfamiliar names, because the brand hosting the event vouches for them, and an early-bird deadline makes people click before they think. Ben Taylor of the risk consultancy Gate 15 went further and challenged the idea that educating attendees is somebody else's job.

Both made the same practical point, which is also the single most useful sentence in the whole story: legitimate event registration almost never needs access to your mailbox, files or contacts. If a consent screen appears after you click an event link, the right move is to close the window.

A registration form needs your name, your email address and a card. The moment it asks for the keys to your inbox instead, it has stopped being a registration form.

What this means for event organisers

The FBI's advice to individuals is standard: scrutinise messages from unfamiliar senders, verify identities independently, and only authorise apps you trust. For an organiser, the job is to make that verification possible, because your attendees cannot check what you never told them.

Start with the setup and configuration of your own comms. Publish the exact domains that official emails and registration pages will use, and put that list in the places attendees already read: the confirmation email, the know-before-you-go message, the event website. Skift's sources recommend telling attendees, in plain words, which apps (if any) will ever ask for account access. For most in-person events the honest answer is "none", and saying so gives every delegate a rule they can apply in two seconds.

The alternative

Tired of Fee Announcements? Go Flat

eventcloud charges one subscription with no per-ticket fees, so platform news stops being budget news.

See pricing

Then look at your vendors, and the question is about permissions rather than features. Ask your registration, housing, mobile app and check-in suppliers what their products request from an attendee's account, and how fast they would tell you about a breach. Taylor's line on that is worth repeating: a vendor that cannot answer clearly has answered.

Finally, plan for the day it happens anyway. A fraudulent message impersonating your registration desk can reach thousands of attendees on move-in morning. Decide now who has the authority to send a warning, which channels it goes out on, and how quickly you can get it there. A one-hour tabletop exercise before a major show costs almost nothing and is the difference between a coordinated response and a Slack thread of panic.

The bit the alert did not cover: what a clean registration flow looks like

The FBI describes the attack. It does not describe the alternative, so here is the shape of a registration and ticketing flow that gives an attacker nothing to imitate.

A trustworthy checkout lives on a domain you have told people about, asks only the questions the organiser configured (name, email, dietary needs, job title, whatever the form needs) and takes payment through a card form from a recognised processor. It never redirects the buyer to a screen that asks them to grant an application access to their Google or Microsoft account. There is no "verify your identity through this app" step, because a ticket purchase does not need one.

That is also the flow eventcloud runs. Attendees fill in the organiser's form and pay through Stripe Checkout, with the money settling into the organiser's own Stripe account. Stripe is the only outside system eventcloud talks to. There is no third-party app in the buyer's path, so there is nothing in that path for an impersonator to copy. You can see how the forms work on the registration feature page.

The wider point is one every organiser can act on regardless of platform: the fewer moving parts between "click the link" and "you are registered", the less there is for a criminal to fake. Every extra app, portal, verification step and connected service is another screen an attacker can clone.

Where this is heading

Skift's sources were candid that AI has made the polished fake invitation cheap to produce, which retires the old advice about spotting typos and awkward phrasing. Combine that with a technique that sidesteps passwords and MFA, and the defensive burden shifts from "can you spot the fake" to "do you know what the real one looks like". Organisers own the second half of that sentence.

The bureau asks anyone who thinks they have been caught to remove the app's access in their account settings, change their password, tell their security team and report it to IC3. Organisers might add one more step: tell your attendees, quickly, before the same link reaches the rest of the list.

Share this article Twitter LinkedIn
Stop paying to succeed

Run Your Next Event on Flat Pricing

Unlimited tickets, registrations and events. One price, no matter how big you grow.

Get in touch! Let's have a chat!