You Changed the Password. They're Still Reading Your Email.

The FBI issued an alert on September 1 about a technique that has been running since late 2025. It does not steal your password. It asks you for permission, and people give it.
The alert is short and worth reading, but it leaves out the part that matters most to a small business: what to actually look for, and why the fix everyone reaches for first does not work.
A password is the lock on your door. What these people get is a key you handed them. Changing the lock doesn't get the key back; the key works in the new lock, and the key is kept in a different drawer than the one everyone knows to check.
What actually happens
You have approved one of these screens before. An app asks to connect to your Google or Microsoft account, and it lists what it wants: see your email, manage your files, send mail as you. You click Allow. That is the normal, legitimate way apps connect to your accounts, and you have probably done it a dozen times with software you use every day.
The attack is that same screen, put in front of you by someone who is not who they say they are.
According to the FBI, the people running this impersonate government officials, media figures, and event coordinators, and they make contact by direct message on ordinary messaging apps. The common cover story is that they want you to look at a draft article or a document. The link goes to a real Google or Microsoft permission screen. You approve it because the screen is genuine, and it is genuine. Only the person who sent it is fake.
What they get is standing access to your account. They can read your mail, reach your files, and send messages as you. No password was stolen. Your multi-factor authentication was never challenged, because from the system's point of view nothing suspicious happened. You gave an app permission, which is a thing people do.
The FBI's alert makes the consequence explicit. That access "can only be revoked by the victim invalidating the token in their application security settings; not by changing the password."
Why the usual fix doesn't work
When people think their account has been compromised, they change the password. It is the right instinct and it is the wrong tool here.
Microsoft publishes a table showing what a password change does and does not cut off. When a person changes their own password, the kind of access these apps hold stays alive. A self-service password reset does not end it either. Only certain specific administrator actions do.
Google is a partial exception, and the difference is worth knowing. Changing your Google password does automatically cut off apps that read your mail. It does not cut off an app holding your files, your contacts, or your calendar. Those keep working.
That inconsistency is the real argument. From the outside you cannot tell which situation you are in. That is why a password change is not the answer, whichever provider you use.
Three more things surprise people, and all three are documented by the providers themselves:
Tightening your company's rules about which apps employees may approve does not remove anything already approved. It closes the door without asking anyone already inside to leave.
Removing the app's permission does not stop the same app from being approved again later.
And on Microsoft, an administrator may not be able to remove a permission an individual employee granted using the normal settings screens at all. It can require tools most small businesses do not have anyone to run. That single fact explains a lot of the cases where this sits undiscovered for months.
There is also a newer version of this going around that defeats even the strongest sign-in protection on the market, because it never asks you to sign in.
The one question to ask
Here is the practical part, and it takes about four minutes.
For a personal Google account, go to myaccount.google.com/linkedapps. Google separates what it finds into categories, and the distinction is the whole exercise. Some entries are Sign in with Google, which means the app only uses Google to log you in. Others say Access to your Google Account, which means the app can reach your actual data.
Sign-in entries are ordinary. Look hard at the ones with access.
Microsoft splits it by account type. For a personal Microsoft account, go to account.microsoft.com/privacy/app-access, which lists what it calls the apps and services that can access some of your info. For a work or school account, the page is myapplications.microsoft.com: hover over an app, click the three dots, then choose Manage your application. Anything you approved yourself, you can remove there. Anything your company's administrator approved for everyone shows up separately, and only they can remove those.
The question is identical on all of them. Does this app need to read my email and my files, or does it just log me in?
Two things to know before you look, because both cause people to draw the wrong conclusion.
Most of what you see will be legitimate and boring. Your phone's mail app, your accounting software, your calendar tool. In a case I worked this year, clearing a client meant going through their connected apps one by one, and everything on the list turned out to be exactly what it appeared to be: the native mail program on their own computer, approved from their own home internet connection, and a pile of sign-in-only entries that looked alarming and meant nothing. Knowing what normal looks like is most of the skill.
The second thing is a timing quirk. On Google's business accounts, a newly approved app can take a day or two to appear in the administrator's list. If something happened this morning and the list looks clean, that is not an all clear yet. Check it again.
The part that should worry a business owner
The FBI alert describes the targets as prominent individuals, and most small business owners will read that and decide it is not about them. The next phrase is the one to pay attention to. It says the attackers also go after those people's family members and personal acquaintances.
You are not necessarily the target. You are the way in, or somebody else is the way in to you.
The case I mentioned is the clearest version of this I have seen. My client lost hundreds of thousands of dollars in a single wire transfer, sent to a criminal who had been quietly reading a genuine email conversation about a real invoice. When we finished the forensics, my client's own accounts were clean. Nobody had touched them. The exposure was at a company they did business with, and the money still left my client's bank.
That is the uncomfortable shape of this. Your own security can be in good order and you can still absorb the loss, because the mailbox being read belongs to someone you trade with.
What to do this week
Open your connected apps list and read it. Remove anything you do not recognize, and anything that has access to your mail or files with no reason to.
If you run a business on Google Workspace or Microsoft 365, ask whoever handles your IT one question: can an employee approve an app's access to their own mailbox without anyone reviewing it? On Microsoft, the answer is yes by default. Changing that setting takes minutes and it prevents the next one.
And if you ever conclude an account was compromised, do not stop at the password. Go and look at what has been given permission, because that is where somebody stays.

