How OAuth Consent Phishing Lets Hackers Access Your Google and Microsoft Accounts

Learn how clicking 'Allow' on OAuth permission screens can expose your account to hackers, why changing passwords won't help, and how to protect yourself by revoking app access.

How OAuth Consent Phishing Lets Hackers Access Your Google and Microsoft Accounts
Sarah Collins

Sarah Collins

Computing Editor

Specializes in PCs, laptops, components, and productivity-focused computing tech.

What is OAuth Consent Phishing and Why Does it Matter?

OAuth consent phishing is a deceptive tactic where attackers trick users into granting a malicious app permission to access their Google, Microsoft, or other service accounts. Unlike traditional phishing that steals passwords directly, this method abuses the OAuth system—a standard that lets apps access your account data without a password. The result? Hackers can read your emails, send messages on your behalf, and harvest sensitive information, all without knowing your password.

This matters because even security-savvy users who use strong passwords and two-factor authentication can fall victim if they unknowingly approve malicious app access. The attack exploits the trust users have in well-known platforms like Google and Microsoft, making it highly effective and dangerous in everyday scenarios like messaging or email use.

How Do OAuth Consent Phishing Attacks Work?

OAuth Consent Phishing: The Attack a Password Change Does Not Fix - DEV  Community
OAuth Consent Phishing: The Attack a Password Change Does Not Fix - DEV Community

Attackers first set up a malicious app that they register as a legitimate application within a platform such as Google or Microsoft. They then contact potential victims via plausible channels—such as instant messaging—masquerading as trusted figures or institutions and share links that appear to lead to documents or important content.

These links direct the victim to authentic OAuth permission request screens hosted by the victim’s trusted service provider. Here, the victim is asked to grant permissions to the malicious app, such as accessing and sending email. If the victim clicks 'Allow', the service issues an access token to the app, giving the attackers full control over the account without ever needing a password.

Why Simply Changing Your Password Won’t Solve the Problem

Because the attackers operate via the OAuth access token, changing the account password does not revoke the token or cut off the app’s access. The credentials that grant the app permission persist independently of password changes. This means the account remains compromised unless the user manually revokes the malicious app’s permission through the security settings of the service provider.

What Should Users Do to Protect Their Accounts?

  • Be cautious when approving OAuth permissions: Only grant app access that you initiated and recognize. Avoid clicking on permission requests prompted by unexpected links or messages, even if they appear to come from known contacts.
  • Regularly review connected apps: Check your Google or Microsoft account security settings to see which apps have access. Revoke permissions for any suspicious or unused applications to eliminate potential backdoors.
  • Use multifactor authentication (MFA): While MFA does not prevent OAuth token abuse, it can add additional protection layers against other account takeover methods.
  • Educate yourself on phishing tactics: Awareness of how attackers impersonate trusted entities can help reduce the chance of falling for fraudulent links or requests.

Practical Takeaway: How to Revoke Malicious App Access

FBI San Antonio on X: "⚠️Cyber criminals are impersonating government  officials, media, and other publicly known personalities on a commercial  messaging application and soliciting the targeted individual to access a  malicious link.
FBI San Antonio on X: "⚠️Cyber criminals are impersonating government officials, media, and other publicly known personalities on a commercial messaging application and soliciting the targeted individual to access a malicious link.

To remove dangerous OAuth tokens if you suspect compromise, follow these steps:

  1. Log into your Google or Microsoft account.
  2. Navigate to the security or app permissions section.
  3. Locate the list of connected third-party apps.
  4. Identify suspicious or unknown apps granted access.
  5. Select and revoke their permissions immediately.

Doing this promptly helps regain control and prevent further unauthorized activity. Combining this with prudent approval habits can significantly reduce the risk posed by OAuth consent phishing.

React to this story

Related Posts