Scam patterns
OAuth-consent phishing
A hostile application asks for access through a real identity-provider screen.
Research articles and reference entries are published in English. Navigation is available in seven languages.
People & projects
In this article
Overview
A hostile application asks for access through a real identity-provider screen.
Why it matters
The password goes to the real provider, but the attacker receives mail, file or contact scopes.
What to check
Review application identity, redirect URI and permissions; preserve consent logs.