Delivery technique · MITRE ATT&CK T1528
OAuth consent phishing
Tricking a user into granting a malicious or look-alike app access to their account, which keeps working after a password reset.
How it works
- The victim is sent to a real consent screen for an attacker-controlled app.
- Approving it issues tokens to the attacker.
- The tokens read mail, files, or CRM data without the password.
Defenses
- Restrict which third-party apps users may approve.
- Review and revoke unused app grants.
- Alert on new apps requesting broad scopes.
Reference: MITRE ATT&CK T1528 Steal Application Access Token
Scams that use it
Cases
2025-06 · US · Disclosed
Google Salesforce instance hit by UNC6040 vishing campaign, 2025