Strike A Nerve – 8/28/2026

Strike A Nerve. Nevtec's weekly cyber threat update graphic featuring a glowing network of connected nodes on a dark blue background.

Your MFA Didn't Fail. Attackers Just Found a Way Around It. 

In this week's "Strike a Nerve" update, I want to talk about a phishing technique that is gaining traction specifically because it does not trigger the alarm most businesses are counting on. 

OAuth 2.0 consent phishing does not try to steal a password. It tricks a user into approving what looks like a legitimate app authorization request. Once approved, the attacker receives an authorization code that grants access to the account, and because no password was stolen, a standard multi factor authentication prompt never fires. One documented case moved from initial contact to a compromised mailbox in under four hours. 

This matters because most businesses treat MFA as the finish line. Turn it on, check the box, move on. But MFA protects against stolen passwords. It was never designed to catch a user clicking allow on a request that looks routine. Attackers have simply found the part of the process that is not being watched. 

The uncomfortable part is that consent phishing works even on employees who would never fall for a fake login page. The request looks like a normal permissions prompt, the kind people click through without reading, every day. 

Three steps to take right now: 

- Ask your IT provider whether your environment monitors for new app authorizations and third-party access grants, not just login attempts. 

- Train your team specifically on what a legitimate app permission request looks like versus a suspicious one, since this is different from standard phishing training. 

- Review currently authorized third-party apps across your business accounts and revoke anything unfamiliar or no longer in use. 

Would your team recognize a fake app authorization request if it landed in their inbox today? Let us help you find out. 

Click here to Know Your Risk! 

— Steve, "Strike a Nerve" Weekly Cyber Threat Update 

Scroll to Top