{"success":true,"data":{"id":"fake-oauth-illicit-consent-grant-phish","label":"OAuth illicit consent grant phish — email masquerades as a Google Docs / Microsoft 365 / DocuSign / Dropbox share and asks the victim to authorize a third-party OAuth app that silently grants attacker persistent mailbox read/send access (Microsoft Digital Defense Report 2025 identified this as the fastest-growing enterprise phishing vector)","description":"Email masquerading as a Google Docs share, Microsoft 365 app consent prompt, DocuSign viewer request, or Dropbox folder access that asks the recipient to authorize a third-party OAuth app. Clicking grant/allow hands the attacker persistent read + send permissions on the victim's mailbox, bypassing password and MFA entirely — the app now IS the account. Microsoft Digital Defense Report 2025 named illicit consent grant the fastest-growing enterprise phishing vector, driving a notable share of business email compromise losses. Genuine Google and Microsoft share notifications never ask the user to authorize a net-new app; the OAuth consent screen itself is hosted on google.com / microsoftonline.com, not a third-party look-alike domain.","tier":"danger","category":"phishing","isThin":false}}