The FBI’s IC3 warns of “OAuth consent phishing” — a technique that bypasses both passwords and MFA by tricking victims into approving a malicious app’s permission request. A password reset doesn’t revoke access; only the victim invalidating the token does.