The FBI is warning that criminals are targeting prominent people and their contacts with "OAuth consent phishing" — a technique that survives a password change entirely — while the FTC is separately warning that scammers are pasting fake QR codes directly over real ones on parking meters.
Never approve an app's permission request from a link a stranger or unexpected message sent you, and don't scan a QR code you find in public — go to the parking or payment app you already trust instead.
Why it's "Elevated" today
We don't predict the future. This level reflects what is verifiably happening right now.
An FBI IC3 public service announcement (I-090126-PSA, September 1, 2026) warns that, since late 2025, criminals have been directly messaging prominent individuals, their family members, and personal acquaintances on commercial messaging apps, impersonating government officials, media, and other public figures to push a malicious link. The link leads to a real "OAuth" permission request for a hostile third-party app — and because the victim grants access rather than typing a password, changing the password afterward does not remove the attacker's access. The FBI advises granting app permissions only to trusted applications and treating messages from unknown senders, even ones with a familiar name attached, with skepticism.
FBI IC3 Public Service Announcement I-090126-PSA (September 1, 2026): Malicious Cyber Actors Gain Access to Victim Accounts Through Consent PhishingA Federal Trade Commission consumer alert (September 3, 2026) warns that people have reported scammers physically covering a legitimate QR code on a parking meter with a fake one of their own. Scanning it can lead to a lookalike payment site built to steal money or personal information. The FTC's advice: check the link a QR reader previews before tapping it, keep your phone's software updated, and use the parking authority's own app or website instead of a code you find pasted somewhere in public.
FTC Consumer Alert (September 3, 2026): See a QR code parked somewhere? Don't scan it...yet!Active right now
The scams behind today's level.
A link from an unexpected message asks you to approve an app's access to your account rather than type a password. Approving it hands over access that a password change alone cannot undo — revoke suspicious app permissions in your account's security settings, and never approve a request that arrived via an unsolicited message.
Read the guideA sticker over a real QR code redirects you to a fake payment page. Skip any QR code you find pasted in public and pay through the parking authority's official app or website instead.
Read the guideEditorial, not algorithmic. Risk levels are a transparent editorial judgment based on a published rubric — with sources, never pseudo-precise scores.
Get the forecast in your inbox
The weekly Deception Forecast — when a scam is spiking, it leads the issue.
Subscribe free