Sentinel Vault
← All field notes
Cyber Leadership & Risk · September 2, 2026

You Changed the Password. They're Still Reading Your Email.

A newly installed door lock lit in cyan with a gold key already turning in it, gold and red lines fanning outward to small houses, offices and storefronts

The FBI issued an alert on September 1 about a technique that has been running since late 2025. It does not steal your password. It asks you for permission, and people give it.

The alert is short and worth reading, but it leaves out the part that matters most to a small business: what to actually look for, and why the fix everyone reaches for first does not work.

A password is the lock on your door. What these people get is a key you handed them. Changing the lock doesn't get the key back; the key works in the new lock, and the key is kept in a different drawer than the one everyone knows to check.

What actually happens

You have approved one of these screens before. An app asks to connect to your Google or Microsoft account, and it lists what it wants: see your email, manage your files, send mail as you. You click Allow. That is the normal, legitimate way apps connect to your accounts, and you have probably done it a dozen times with software you use every day.

The attack is that same screen, put in front of you by someone who is not who they say they are.

According to the FBI, the people running this impersonate government officials, media figures, and event coordinators, and they make contact by direct message on ordinary messaging apps. The common cover story is that they want you to look at a draft article or a document. The link goes to a real Google or Microsoft permission screen. You approve it because the screen is genuine, and it is genuine. Only the person who sent it is fake.

What they get is standing access to your account. They can read your mail, reach your files, and send messages as you. No password was stolen. Your multi-factor authentication was never challenged, because from the system's point of view nothing suspicious happened. You gave an app permission, which is a thing people do.

The FBI's alert makes the consequence explicit. That access "can only be revoked by the victim invalidating the token in their application security settings; not by changing the password."

Why the usual fix doesn't work

When people think their account has been compromised, they change the password. It is the right instinct and it is the wrong tool here.

Microsoft publishes a table showing what a password change does and does not cut off. When a person changes their own password, the kind of access these apps hold stays alive. A self-service password reset does not end it either. Only certain specific administrator actions do.

Google is a partial exception, and the difference is worth knowing. Changing your Google password does automatically cut off apps that read your mail. It does not cut off an app holding your files, your contacts, or your calendar. Those keep working.

That inconsistency is the real argument. From the outside you cannot tell which situation you are in. That is why a password change is not the answer, whichever provider you use.

Three more things surprise people, and all three are documented by the providers themselves:

Tightening your company's rules about which apps employees may approve does not remove anything already approved. It closes the door without asking anyone already inside to leave.

Removing the app's permission does not stop the same app from being approved again later.

And on Microsoft, an administrator may not be able to remove a permission an individual employee granted using the normal settings screens at all. It can require tools most small businesses do not have anyone to run. That single fact explains a lot of the cases where this sits undiscovered for months.

There is also a newer version of this going around that defeats even the strongest sign-in protection on the market, because it never asks you to sign in.

The one question to ask

Here is the practical part, and it takes about four minutes.

For a personal Google account, go to myaccount.google.com/linkedapps. Google separates what it finds into categories, and the distinction is the whole exercise. Some entries are Sign in with Google, which means the app only uses Google to log you in. Others say Access to your Google Account, which means the app can reach your actual data.

Sign-in entries are ordinary. Look hard at the ones with access.

Microsoft splits it by account type. For a personal Microsoft account, go to account.microsoft.com/privacy/app-access, which lists what it calls the apps and services that can access some of your info. For a work or school account, the page is myapplications.microsoft.com: hover over an app, click the three dots, then choose Manage your application. Anything you approved yourself, you can remove there. Anything your company's administrator approved for everyone shows up separately, and only they can remove those.

The question is identical on all of them. Does this app need to read my email and my files, or does it just log me in?

Two things to know before you look, because both cause people to draw the wrong conclusion.

Most of what you see will be legitimate and boring. Your phone's mail app, your accounting software, your calendar tool. In a case I worked this year, clearing a client meant going through their connected apps one by one, and everything on the list turned out to be exactly what it appeared to be: the native mail program on their own computer, approved from their own home internet connection, and a pile of sign-in-only entries that looked alarming and meant nothing. Knowing what normal looks like is most of the skill.

The second thing is a timing quirk. On Google's business accounts, a newly approved app can take a day or two to appear in the administrator's list. If something happened this morning and the list looks clean, that is not an all clear yet. Check it again.

The part that should worry a business owner

The FBI alert describes the targets as prominent individuals, and most small business owners will read that and decide it is not about them. The next phrase is the one to pay attention to. It says the attackers also go after those people's family members and personal acquaintances.

You are not necessarily the target. You are the way in, or somebody else is the way in to you.

The case I mentioned is the clearest version of this I have seen. My client lost hundreds of thousands of dollars in a single wire transfer, sent to a criminal who had been quietly reading a genuine email conversation about a real invoice. When we finished the forensics, my client's own accounts were clean. Nobody had touched them. The exposure was at a company they did business with, and the money still left my client's bank.

That is the uncomfortable shape of this. Your own security can be in good order and you can still absorb the loss, because the mailbox being read belongs to someone you trade with.

What to do this week

Open your connected apps list and read it. Remove anything you do not recognize, and anything that has access to your mail or files with no reason to.

If you run a business on Google Workspace or Microsoft 365, ask whoever handles your IT one question: can an employee approve an app's access to their own mailbox without anyone reviewing it? On Microsoft, the answer is yes by default. Changing that setting takes minutes and it prevents the next one.

And if you ever conclude an account was compromised, do not stop at the password. Go and look at what has been given permission, because that is where somebody stays.

About the author
Pete Hish, Sentinel Vault founder
Taught by Pete Hish · Founder

A working cyber-fraud supervisor, not a vendor consultant.

US Army veteran. Active sergeant supervising a cyber and fraud investigations team at a large Southern California law-enforcement agency. Ten-plus years inside the cases that hit small businesses, families, and public-sector agencies first. The training is shaped by what actually goes wrong, not what vendor decks predict.

Certified Cybersecurity SpecialistCertified Cyber Fraud SpecialistCalifornia POST Certified Instructor
Hacked or Hardened? book cover
Prefer the long-form version?

Hacked or Hardened? covers these patterns end-to-end: the four ways small businesses get hit, what to fix first, and how to lead through an incident.

Keep pulling the thread
The fiction version

Fleeced Nation is a crime series about industrialized fraud, from the elder-fraud call centers to the quiet machinery that turns dirty cash clean. Same terrain as the case files, minus the parts a report will not hold. I started it as fiction. The case files keep publishing the sequel.

fleecednation.com ↗
Related field notes
Next step

Want this kind of analysis for your team?

A 2–4 hour cyber risk briefing: the threats specific to your business, the controls that actually pull their weight, and a 90-day action plan.