Skip to content
CIM-037 Cyber Incidents & Offender Methods

What is consent phishing?

Consent phishing is an attempt to persuade a user to grant a malicious or deceptive application permission to access an account or organisational data.

Avoid the dangerous assumption

The dangerous assumption is that account compromise always involves stealing the password.

It does not.

A user may authenticate legitimately to a genuine identity provider and then approve permissions requested by an application controlled by an offender.

Those permissions may allow the application to:

  • read email
  • access files
  • view profile information
  • send messages
  • maintain access
  • use organisational data through an API.

The exact effect depends on the permissions granted, the provider and the organisation’s configuration.

Investigators should preserve:

  • the application name and identifier
  • the publisher or developer information
  • the permissions requested and granted
  • the consenting account
  • the consent timestamp
  • the application’s redirect addresses
  • subsequent API or account activity
  • any administrator approval
  • revocation and containment actions.

Do not rely only on the application’s display name. Names and logos can be misleading. Stable application and tenant identifiers are more useful.

Consent does not necessarily mean the user understood the consequences. It also does not prove that every granted permission was used.

The presence of a malicious application may provide continuing access even after the password is changed. Current provider behaviour should be verified before making specific claims about revocation.

Separate account attribution from personal attribution. The consent event may be associated with an account, but the account may have been shared, remotely controlled or already compromised.

Operational takeaway

Check whether access was granted through application consent rather than password theft, and preserve the application, permission, account and subsequent activity records.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.