Consent Phishing

Noun · Security & Infosec

Definitions

  1. A phishing technique that tricks users into granting malicious applications access through legitimate consent flows, often in cloud identity platforms. Because the victim authorizes the access themselves, traditional password-focused defenses may not stop it.

    In plain English: A phishing trick where users are fooled into granting app permissions themselves.

    Example: "The incident was consent phishing: the employee approved a malicious app that then accessed mailbox data through the provider's APIs."

Related Terms