Consent Phishing: Malicious App Permission Requests
Consent phishing asks you to approve an app that then reads your email and files, without ever stealing your password. How it works and how to spot and revoke malicious app permissions.

Consent phishing is clever because it does not need your password. You click a link, sign in on the genuine Microsoft or Google page, and see a request: "This app would like to read your mail, access your files and maintain access." If you click Accept, the attacker's app gets exactly that.
How it works
- An email invites you to use a helpful-sounding app: a document viewer, a scheduler, a "security scanner".
- You sign in on the real provider's page, so everything looks legitimate.
- A consent screen asks for permissions such as reading mail, files or contacts.
- You click Accept. The app receives a token that works even if you later change your password.
Red flags on consent screens
- An app you did not go looking for.
- Broad permissions: read and send mail, read all files, access when you are not present.
- An unfamiliar or unverified publisher.
- A name that mimics a well-known tool.
Read consent screens before clicking Accept. If an app wants access to your email or files and you did not seek it out, decline.
If you accepted
- Revoke the app in your account's connected apps settings. See connected apps.
- At work, report it to IT immediately.
- Check for forwarding rules and sent messages. See hidden forwarding rules.
For organizations
- Limit user consent to verified publishers and low-risk permissions.
- Require admin approval for sensitive permissions.
- Review app grants regularly and alert on new high-privilege consents.
Got an email inviting you to connect an app? Paste it into CyberWatch AI Scan for a free check.
For all the types of phishing, read our complete guide.
Frequently asked questions
How is consent phishing different from normal phishing?
You sign in on the real provider's page, and you are asked to grant permissions to an app. If you accept, the app gets access without needing your password.
Does changing my password remove the app's access?
Not necessarily. You need to revoke the app's permissions in your account's connected apps settings.
How can organizations prevent it?
Restrict which apps users can approve, require admin approval for sensitive permissions, and review connected apps regularly.
Sources
- Privacy Checkup, Google
- How Websites and Apps Collect and Use Your Information, US Federal Trade Commission
- Cyber Essentials, US Cybersecurity and Infrastructure Security Agency


