Skip to main content

Aug 12, 2026

The App You Approved in Ten Seconds

A single click on an OAuth consent screen can hand an attacker standing access that outlives every password reset

Someone gets an email about a shared document, clicks through, and lands on a familiar Microsoft or Google consent screen. An app is requesting access to read mail and files. They click Accept. That click just granted a third party a token, and that token does not expire when they change their password.

Consent phishing skips credential theft. There is no fake login page to spot, because the attacker never wanted the password. They wanted the grant, an OAuth token that keeps reading mail and pulling files long after the user has forgotten the app exists.

Why the Grant Slips Through

Most controls scrutinize authentication and ignore authorization. The consent moment looks like a routine productivity action, one of dozens of app approvals in a week. Nothing about the click trips a sign-in alarm, and the app's access persists quietly in the background.

Watch What the App Does, Not Just That It Was Approved

PeopleBase profiles both the user and the apps connected to them, so a newly consented app that immediately reads mail in bulk, or sweeps files the user rarely opens, deviates the moment it acts, long before anyone reviews the app list again. The grant looked like routine productivity. The first thing the app did with it fit no pattern the real user has.

Attackers stopped asking for passwords they can lose to a reset. They ask for permissions instead. Watch the permissions.

See the latest from Abnormal's product and engineering teams.

Protect Against Evolving Email Threats

See how behavioral AI detects attacks that legacy defenses miss.