OAuth Consent Phishing ('Sign in with Google/Apple')
You're tricked into approving a real 'sign in with' or 'allow access' prompt for a malicious app, granting it ongoing access to your email or files without your password.
Think a message like this reached you? You can check it right now.
What this scam is
Instead of stealing your password, this attack gets you to approve a legitimate-looking permission prompt (via 'Sign in with Google/Microsoft' or 'Allow this app to access your account'). Approving grants a malicious third-party app a token that lets it read your email, files, or contacts continuously — even if you later change your password, until you revoke the app's access. The lure is often a shared 'document' or a useful-looking app.
What it usually looks like
- A prompt to authorize an app to access your account.
- A shared 'document' or app that needs 'permission.'
- Requests for broad access (read email, files, contacts).
- An app name you don't recognize.
Common warning signs
- Being asked to 'allow access' to an unfamiliar app.
- Broad permissions for a simple task.
- Prompts arriving from a shared link or DM.
- Pressure to approve to view content.
Example wording scammers use
“'DocViewer' wants to access your Google account: read, send, and manage your email. [Allow] [Deny]”
“Sign in to view the shared file — approve access to continue.”
These are illustrative examples written by ScamSplain, not real messages.
What the scammers want
- An access token via your approval.
- Ongoing access to your email/files.
- To bypass your password entirely.
What to do
- Read permission prompts carefully; deny apps you don't recognize.
- Don't grant broad access for a simple 'document.'
- Periodically review and revoke third-party app access in your account security settings.
- Report suspicious prompts to IT.
What to do if you already responded
- Revoke the app's access in your Google/Microsoft security settings immediately.
- Change your password and review email rules/sent items.
- Report internally and at reportfraud.ftc.gov.