Mon, Aug 31 Deception Forecast · Monday, September 7, 2026 Mon, Sep 14
Scam risk level
Elevated
Elevated · a new FBI warning on a password-proof account takeover technique, plus a fresh FTC alert on a physical QR-code swap showing up in parking lots
Watch
Elevated
High
Severe
Today's headline threat

The FBI is warning that criminals are targeting prominent people and their contacts with "OAuth consent phishing" — a technique that survives a password change entirely — while the FTC is separately warning that scammers are pasting fake QR codes directly over real ones on parking meters.

Defense move

Never approve an app's permission request from a link a stranger or unexpected message sent you, and don't scan a QR code you find in public — go to the parking or payment app you already trust instead.

This forecast is a nowcast.Every level is backed by verified activity or a documented seasonal pattern — never a guess.

Why it's "Elevated" today

We don't predict the future. This level reflects what is verifiably happening right now.

Verified activity

An FBI IC3 public service announcement (I-090126-PSA, September 1, 2026) warns that, since late 2025, criminals have been directly messaging prominent individuals, their family members, and personal acquaintances on commercial messaging apps, impersonating government officials, media, and other public figures to push a malicious link. The link leads to a real "OAuth" permission request for a hostile third-party app — and because the victim grants access rather than typing a password, changing the password afterward does not remove the attacker's access. The FBI advises granting app permissions only to trusted applications and treating messages from unknown senders, even ones with a familiar name attached, with skepticism.

FBI IC3 Public Service Announcement I-090126-PSA (September 1, 2026): Malicious Cyber Actors Gain Access to Victim Accounts Through Consent Phishing
Verified activity

A Federal Trade Commission consumer alert (September 3, 2026) warns that people have reported scammers physically covering a legitimate QR code on a parking meter with a fake one of their own. Scanning it can lead to a lookalike payment site built to steal money or personal information. The FTC's advice: check the link a QR reader previews before tapping it, keep your phone's software updated, and use the parking authority's own app or website instead of a code you find pasted somewhere in public.

FTC Consumer Alert (September 3, 2026): See a QR code parked somewhere? Don't scan it...yet!
We never invent a number or a "tomorrow." If we can't source it, we don't raise the level. How we forecast ›

Active right now

The scams behind today's level.

ElevatedOAuth "consent phishing" that survives a password reset

A link from an unexpected message asks you to approve an app's access to your account rather than type a password. Approving it hands over access that a password change alone cannot undo — revoke suspicious app permissions in your account's security settings, and never approve a request that arrived via an unsolicited message.

Read the guide
ElevatedQR code swapped onto a parking meter or public sign

A sticker over a real QR code redirects you to a fake payment page. Skip any QR code you find pasted in public and pay through the parking authority's official app or website instead.

Read the guide

Editorial, not algorithmic. Risk levels are a transparent editorial judgment based on a published rubric — with sources, never pseudo-precise scores.

Get the forecast in your inbox

The weekly Deception Forecast — when a scam is spiking, it leads the issue.

Subscribe free