A consent phishing scam tricked a user into granting access to their account to a malicious third-party app.
This technique is effective against users with strong passwords, multi-factor authentication, and even passwordless accounts.
The attacker first registers an OAuth 2.0 app with the target platform (e.g. Microsoft 365 or Google Workspace).
Depending on the platform, this may require minimal requirements.
Through phishing tactics, users are then lured into giving the app access to their accounts.
The user is then presented with a legitimate consent screen for the target platform.
Using these permissions, attackers can read and write any files you have access to.
Also, they got permission to send emails as you.
In the final step, the attackers requested permission to set up a mail forwarding rule in your email settings.
It will forward all your emails to them directly without requiring them to log in.
Attackers can continue doing this until you delete the 0Auth app underlying it.
So, think twice before granting access to any unknown app.