Skip to content

Workforce and access social engineering · Also called connected app vishing, OAuth vishing, Salesforce Data Loader vishing, UNC6040, malicious app authorization call

Vishing into a malicious OAuth connected app

Vishing into a connected app is an attack in which a caller posing as IT support talks an employee into authorising a malicious app on a company cloud service, often by entering a connection code. The app then gets standing access to company data, which the attackers export and later use for extortion.

How it works

  1. An attacker calls an employee while posing as IT support.
  2. The caller guides the employee to the service's connected app setup page and asks them to enter a connection code, which authorises an attacker-controlled app, sometimes a modified data export tool with a harmless-sounding name.
  3. The app's OAuth access lets the attackers query and export large amounts of data, and any passwords or MFA codes given on the call help them reach other cloud services.
  4. Weeks or months later, the victim receives an extortion demand, for example for bitcoin within 72 hours, threatening to publish the data.

Red flags

If you are targeted

Where to report, by country

Prevention

For individuals

For organisations

By the numbers

Figures are for the reporting category this scam falls under, not this scam alone.

Phishing and spoofing losses reported to the FBI IC3 in 2025$215.8MUS, 2025, FBI IC3

Real cases

Delivered through: Voice phishing (vishing), OAuth consent phishing

How official datasets classify it

FBI IC3
Phishing/Spoofing
MITRE ATT&CK
T1566.004, T1528

Questions

How can a phone call give attackers access to our cloud data?
The caller does not need your password. Google Threat Intelligence describes callers posing as IT support who guide employees to approve a malicious connected app, which then has OAuth access to query and export data.
How do we stop malicious connected apps?
Only let a few administrators authorise new apps, keep an allowlist, limit bulk export permissions, and watch for large downloads. Train staff never to approve an app or enter a code because a caller asked.

Related scams

Read more