What is OAuth Phishing?
OAuth phishing does not always steal your password. It tricks you into clicking "Allow" on a third-party app consent screen, granting mailbox or files access to an attacker-controlled application — access that can survive a password change.
How a OAuth Phishing Attack Works
Register a malicious app
The app requests broad Microsoft 365 or Google Workspace scopes.
Send a legitimate-looking consent link
Email or chat frames it as a document share, calendar tool, or HR form.
Harvest the grant
Once allowed, the attacker API-accesses mail and files without your password.
Persist
Tokens and app permissions remain until an admin revokes them.
Real-World Example
Employees approved an "HR benefits portal" OAuth app after a spear-phish referenced a real open-enrollment date from the company blog. The app silently forwarded executive mail for weeks.
How AiVERSARY Detects OAuth Phishing Risk
AiVersary calls out public cues attackers use to impersonate internal tools and vendors in consent lures — and pairs that with tenant-exposure themes in related infrastructure findings.
Is your organization exposed to oauth phishing?
AiVERSARY scans your public footprint and identifies the exact data attackers would use against you. $499 per report.
Get Your Threat ReportRelated Terms
Tenant Compromise
Tenant compromise is when an attacker gains administrative control over your organization's cloud environment — your Microsoft 365 tenant, Google Workspace, or AWS account. Unlike stealing a single employee's password, this gives the attacker the keys to everything: every email, every file, every application, and every user account in your cloud infrastructure. It is the most devastating outcome of a successful credential attack.
Spear Phishing
Spear phishing is a targeted email attack where criminals research a specific person and craft a message designed just for them. Unlike mass spam, these emails reference real details about your job, your colleagues, or recent company events to appear legitimate. They are the number one way attackers breach organizations today.
Business Email Compromise
Business email compromise is when an attacker impersonates a senior executive — usually the CEO or CFO — to trick an employee into wiring money or sharing sensitive data. These attacks don't require any malware or hacking; they rely entirely on convincing someone that a fraudulent request is coming from their boss. The FBI reports BEC has caused over $50 billion in losses worldwide.
MFA Fatigue
MFA fatigue is an attack where a criminal who already has your password repeatedly triggers multi-factor authentication prompts — the push notifications on your phone — until you approve one just to make them stop. It exploits the very security measure designed to protect you by turning it into an annoyance that people instinctively dismiss. This technique has been used in several high-profile breaches.