Service-account or non-human identity abuse
OAuth consent phishing
Also called: illicit consent grant
OAuth consent phishing is an attack that tricks a user or administrator into authorizing a malicious application to access their account or organization. Instead of stealing a password, the attacker gets an OAuth token through the normal consent screen. The app keeps that access even after a password reset, and it can bypass MFA.
How it works
The attacker registers an app with a trustworthy name and sends a link, or talks the target through approving it by phone. The consent prompt lists permissions such as reading mail or files, and the user clicks accept. The app then uses its token to pull data through the provider's API, which can look like a legitimate integration.
A real example
A September 2025 FBI FLASH said UNC6040 threat actors deceived victims into authorizing malicious connected apps to their organizations' Salesforce portals, and noted that authorizing such an app bypasses defenses like MFA and password resets.
Source: Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion (FLASH-20250912-001) — Federal Bureau of Investigation (FBI), 2025-09-12
How to stop it
Restrict which users can consent to apps, require admin approval for apps that request sensitive scopes, and review and revoke unused app grants regularly.
Related terms
Sources
- Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion (FLASH-20250912-001) — Federal Bureau of Investigation (FBI), 2025-09-12
Last reviewed Oct 2, 2026