Avatier

Service-account or non-human identity abuse

OAuth consent phishing

Also called: illicit consent grant

OAuth consent phishing is an attack that tricks a user or administrator into authorizing a malicious application to access their account or organization. Instead of stealing a password, the attacker gets an OAuth token through the normal consent screen. The app keeps that access even after a password reset, and it can bypass MFA.

How it works

The attacker registers an app with a trustworthy name and sends a link, or talks the target through approving it by phone. The consent prompt lists permissions such as reading mail or files, and the user clicks accept. The app then uses its token to pull data through the provider's API, which can look like a legitimate integration.

A real example

A September 2025 FBI FLASH said UNC6040 threat actors deceived victims into authorizing malicious connected apps to their organizations' Salesforce portals, and noted that authorizing such an app bypasses defenses like MFA and password resets.

Source: Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion (FLASH-20250912-001) — Federal Bureau of Investigation (FBI), 2025-09-12

How to stop it

Restrict which users can consent to apps, require admin approval for apps that request sensitive scopes, and review and revoke unused app grants regularly.

Related terms

Sources

  1. Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion (FLASH-20250912-001) — Federal Bureau of Investigation (FBI), 2025-09-12

Last reviewed Oct 2, 2026