Microsoft 365Incident TeardownsRetrospectives

Illicit Consent Grant Phishing (July 2020): Attackers Stop Stealing Passwords

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from July 2020, written in 2026 with the benefit of hindsight.

In July 2020, Microsoft warned about a rise in consent phishing (also called illicit consent grant) campaigns, many using COVID-19 themes. Instead of stealing passwords, attackers tricked users into granting malicious applications access to their Microsoft 365 data.

How consent phishing works

  1. The attacker registers an application with an innocent-sounding name and logo.
  2. Users receive an email with a link to a genuine Microsoft sign-in page.
  3. After signing in normally, users see a consent prompt asking to allow the app to read their mail, files, contacts or calendar.
  4. If the user accepts, the app receives OAuth tokens — and can access that data without the user's password, often for an extended period.

Because the sign-in page is real and the user completes MFA themselves, traditional phishing defenses and MFA don't stop it. Resetting the user's password doesn't revoke the app's access either.

Microsoft's response

Microsoft's Digital Crimes Unit took legal action to seize domains used in a large consent phishing campaign, and Microsoft introduced publisher verification, consent controls and risk-based step-up consent.

Lessons in hindsight

  • Restrict user consent to verified publishers and low-risk permissions.
  • Use an admin consent workflow for everything else.
  • Monitor and review OAuth apps with high-impact permissions.
  • Train users that "Accept" on a permission screen is a security decision.

In hindsight

OAuth abuse grew into one of the most important attack techniques in cloud environments, including in the 2024 breach of Microsoft by Midnight Blizzard and the 2025 Salesloft Drift campaign. Consent phishing was an early, user-facing version of the same problem.

consent phishing2020

More on this story