Scam alert
A Message Asks You to 'Approve' an App? Check Before You Tap Allow
Published · Arrives by a direct message on a messaging app
The short answer
Do not tap Allow on a permission screen that arrived through a link someone sent you, even if the message looks like it comes from someone you know. The screen itself is real, run by a real communication provider, but approving it can give a stranger's app lasting access to your email and files. If you already approved one, a password change will not remove that access—open your account's security settings and revoke the app's permission directly, then report what happened.
What is happening
The FBI's Internet Crime Complaint Center said in a September 2026 alert that since late 2025, people have been contacted directly on messaging apps by someone posing as a journalist, an event planner, or another familiar role, asking them to open a link to review a document or confirm an event. The link leads to a genuine Microsoft or Google permission screen. Approving it hands a third-party app standing access to the account's email and files, and that access continues even after the password is changed.
How to recognize it
- A direct message from an unfamiliar number or account asks you to click a link to view a shared document, confirm an event, or verify who you are.
- The link opens a real-looking Microsoft or Google sign-in and permission screen rather than a fake-looking page.
- The screen asks you to approve an application's access to your mail, files, or contacts, not just to sign in.
- The message creates a reason to act through an unfamiliar app rather than the service you normally use.
What to do instead
- Do not open permission or 'approve access' links sent through a direct message, even from a name you recognize.
- If you want to see a shared document, go to the service directly and check whether anything was actually shared with you.
- Before approving any app's request for account access, read what it is asking for—access to read and send mail is a large grant for a document viewer.
- Confirm unusual requests with the sender through a different, independently found contact method.
If it already happened
Responding to one of these is common and understandable. These steps are what people usually take next.
- Go to your account's security or app-permissions settings and revoke the application's access directly—changing your password alone does not remove it.
- Review your account's sent mail and file activity for anything you do not recognize.
- Turn on alerts for new sign-ins and connected apps if your account offers them.
- Report it to the FBI's Internet Crime Complaint Center at ic3.gov.
Common questions
- If I already changed my password, am I safe?
- Not on its own. This kind of access is granted through an app permission, not a password, so it survives a password change. You have to open your account's security settings and revoke the specific app.
- How do I know if an app has access to my account right now?
- Google and Microsoft accounts both have a page listing connected apps and what each one can do. Reviewing it occasionally and removing anything you do not recognize or no longer use is a reasonable habit.
- The message came from a contact I know. Does that make it safe?
- No. These messages often arrive from an account or number made to look familiar, or from a contact whose own account was already reached this way. Confirm through a separate channel before opening a permission link.
Practice this safely
Practice pausing on a message that wants you to approve an app, rather than just sign in, before you tap anything.
Every story is fictional. There is no timer, no score, and no real message, payment, or account.
Where this comes from
These links open the published sources in a new tab. The destination is shown before you open it.
The full guide on this
More recent alerts
This alert provides general educational information drawn from the sources above. It cannot determine whether a specific message you received is genuine, investigate an incident, or promise recovery or reimbursement.