Someone gets an email about a shared document, clicks through, and lands on a familiar Microsoft or Google consent screen. An app is requesting access to read mail and files. They click Accept. That click just granted a third party a token, and that token does not expire when they change their password.
Consent phishing skips credential theft. There is no fake login page to spot, because the attacker never wanted the password. They wanted the grant, an OAuth token that keeps reading mail and pulling files long after the user has forgotten the app exists.
Why the Grant Slips Through
Most controls scrutinize authentication and ignore authorization. The consent moment looks like a routine productivity action, one of dozens of app approvals in a week. Nothing about the click trips a sign-in alarm, and the app's access persists quietly in the background.
Watch What the App Does, Not Just That It Was Approved
PeopleBase profiles both the user and the apps connected to them, so a newly consented app that immediately reads mail in bulk, or sweeps files the user rarely opens, deviates the moment it acts, long before anyone reviews the app list again. The grant looked like routine productivity. The first thing the app did with it fit no pattern the real user has.
Attackers stopped asking for passwords they can lose to a reset. They ask for permissions instead. Watch the permissions.
See the latest from Abnormal's product and engineering teams.

