{"id":3837,"date":"2026-08-20T08:32:10","date_gmt":"2026-08-20T06:32:10","guid":{"rendered":"https:\/\/trustlab.upct.es\/?p=3837"},"modified":"2026-07-16T01:15:24","modified_gmt":"2026-07-15T23:15:24","slug":"consent-phishing","status":"publish","type":"post","link":"https:\/\/trustlab.upct.es\/en\/2026\/08\/20\/consent-phishing\/","title":{"rendered":"Consent Phishing: The Attack That Does Not Need Your Password"},"content":{"rendered":"<p>You receive an email containing a link to view a document, install a tool or access a service.<\/p>\n<p>You click it. The genuine Microsoft or Google sign-in page appears. You log in as usual and complete multifactor authentication.<\/p>\n<p>Everything looks legitimate.<\/p>\n<p>Then, another screen asks for permission to read your email, access your files, view your contacts or maintain access to your account.<\/p>\n<p>You click \u201cAllow.\u201d<\/p>\n<p>The attacker did not need to steal your password. You authorized the access yourself.<\/p>\n<h2>Authentication Is Not the Same as Authorization<\/h2>\n<p>When we sign in, we prove who we are. That is authentication.<\/p>\n<p>When we allow an application to access certain data or perform actions on our behalf, that is authorization.<\/p>\n<p>Services such as Microsoft 365 and Google Workspace allow us to connect external applications without sharing our passwords directly. Instead, the application receives limited access (represented by a token) to the resources the user has authorized.<\/p>\n<p>This is a legitimate and useful mechanism. It enables us to connect calendars, productivity tools, document managers and many other services.<\/p>\n<p>The problem arises when a malicious application persuades us to grant those permissions.<\/p>\n<h2>A Legitimate Page Can Still Lead to a Dangerous Decision<\/h2>\n<p>In traditional phishing, attackers often create a fake website to capture usernames and passwords.<\/p>\n<p>In consent phishing, the sign-in page may be completely genuine. The address may really belong to Microsoft or Google, and multifactor authentication may work exactly as expected.<\/p>\n<p>The deception is not necessarily on the page where we authenticate. It lies in the application requesting access and in the permissions we are about to grant.<\/p>\n<p>This can create a false sense of security:<\/p>\n<blockquote><p>\u201cThe page is official, so it must be safe.\u201d<\/p><\/blockquote>\n<p>But a legitimate platform does not automatically make the connected application trustworthy.<\/p>\n<h2>What Can an Authorized Application Do?<\/h2>\n<p>That depends on the permissions granted. An application may request the ability to:<\/p>\n<ul>\n<li>Read your email.<\/li>\n<li>View or modify your files.<\/li>\n<li>Access your contacts and calendars.<\/li>\n<li>Send messages on your behalf.<\/li>\n<li>View your profile information.<\/li>\n<li>Maintain access even when you are no longer using the application.<\/li>\n<\/ul>\n<p>These permissions are not inherently dangerous. Many legitimate applications need them to function.<\/p>\n<p>The warning sign appears when the access requested is excessive, unexpected or unrelated to the service being offered.<\/p>\n<p>A tool that claims to let you view a single document should not normally require permanent access to your entire mailbox.<\/p>\n<h2>What to Check Before Clicking \u201cAllow\u201d<\/h2>\n<p>Before authorizing an application, pause for a few seconds and check:<\/p>\n<ol>\n<li>Who is requesting access. Review the name of the application and its developer. Be cautious with generic names or names that closely imitate familiar services.<\/li>\n<li>How you reached the page. A request opened through an unexpected email, urgent message or chat link deserves particular scrutiny.<\/li>\n<li>Which permissions are being requested. Read the full list. Do not stop after confirming that the page belongs to Microsoft or Google.<\/li>\n<li>Whether the permissions are proportionate. Ask whether the application genuinely needs that level of access to do what it promises.<\/li>\n<li>Whether you are being pressured to act quickly. Urgency is commonly used to make people approve requests without thinking.<\/li>\n<\/ol>\n<p>If something does not make sense, cancel the request. Access the service through its official website or ask your support team to verify it.<\/p>\n<h2>Changing the Password May Not Be Enough<\/h2>\n<p>When we suspect that an account has been compromised, our first reaction is usually to change the password.<\/p>\n<p>That is a sensible measure, but in this case it may not solve the entire problem.<\/p>\n<p>Once an application has been authorized, it may retain a token that allows it to continue accessing certain resources without needing the new password.<\/p>\n<p>You should also:<\/p>\n<ul>\n<li>Review the applications connected to the account.<\/li>\n<li>Revoke any authorization you do not recognize.<\/li>\n<li>Check the permissions already granted.<\/li>\n<li>Review recent activity and active sessions.<\/li>\n<li>Report the incident to the security team if it involves a professional or institutional account.<\/li>\n<\/ul>\n<p>The password protects the sign-in process. Permissions determine what an application can do once it has been allowed inside.<\/p>\n<h2>Before Authorizing, Look Beyond the Domain<\/h2>\n<p>Checking the address of a webpage remains important, but it is no longer always enough.<\/p>\n<p>A legitimate screen can present a dangerous request. Multifactor authentication may confirm that you are really you, but it cannot decide whether the application deserves your trust.<\/p>\n<p>That decision is still yours.<\/p>\n<p>The next time an application asks to access your email, files, contacts or calendar, do not click \u201cAllow\u201d automatically.<\/p>\n<p>Check who is asking, which permissions are being requested and what the application will be able to do on your behalf.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A legitimate sign-in page does not guarantee that an authorization request is safe. Learn how consent phishing can access your email, files or contacts without stealing your password.<\/p>\n","protected":false},"author":8,"featured_media":3836,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34],"tags":[69,78,77,70,76,73,75],"class_list":["post-3837","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tips","tag-account-security","tag-connected-applications","tag-consent-phishing","tag-digital-identity","tag-identidad-digital","tag-oauth","tag-seguridad-de-cuentas"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"A legitimate sign-in page does not guarantee that an authorization request is safe. Learn how consent phishing can access your email, files or contacts without stealing your password.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"mdcano\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/trustlab.upct.es\/en\/2026\/08\/20\/consent-phishing\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"TRUST Lab - Sitio dedicado a la investigaci\u00f3n, desarrollo y formaci\u00f3n en ciberseguridad y tecnolog\u00edas digitales avanzadas.\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Consent Phishing: The Attack That Does Not Need Your Password - TRUST Lab\" \/>\n\t\t<meta property=\"og:description\" content=\"A legitimate sign-in page does not guarantee that an authorization request is safe. Learn how consent phishing can access your email, files or contacts without stealing your password.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/trustlab.upct.es\/en\/2026\/08\/20\/consent-phishing\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/trustlab.upct.es\/wp-content\/uploads\/2024\/05\/TL-logo.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/trustlab.upct.es\/wp-content\/uploads\/2024\/05\/TL-logo.png\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-08-20T06:32:10+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-07-15T23:15:24+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Consent Phishing: The Attack That Does Not Need Your Password - TRUST Lab\" \/>\n\t\t<meta name=\"twitter:description\" content=\"A legitimate sign-in page does not guarantee that an authorization request is safe. Learn how consent phishing can access your email, files or contacts without stealing your password.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/trustlab.upct.es\/wp-content\/uploads\/2024\/05\/TL-logo.png\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/2026\\\/08\\\/20\\\/consent-phishing\\\/#blogposting\",\"name\":\"Consent Phishing: The Attack That Does Not Need Your Password - TRUST Lab\",\"headline\":\"Consent Phishing: The Attack That Does Not Need Your Password\",\"author\":{\"@id\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/author\\\/mdcano\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/trustlab.upct.es\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/phishing-consentimiento-oauth.jpg\",\"width\":1672,\"height\":941,\"caption\":\"Aplicaci\\u00f3n solicitando permisos de acceso a una cuenta mediante OAuth\"},\"datePublished\":\"2026-08-20T08:32:10+02:00\",\"dateModified\":\"2026-07-16T01:15:24+02:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/2026\\\/08\\\/20\\\/consent-phishing\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/2026\\\/08\\\/20\\\/consent-phishing\\\/#webpage\"},\"articleSection\":\"Tips, account security, connected applications, consent phishing, digital identity, identidad digital, OAuth, seguridad de cuentas, Opcional\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/2026\\\/08\\\/20\\\/consent-phishing\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/#listItem\",\"position\":1,\"name\":\"Hogar\",\"item\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/category\\\/tips\\\/#listItem\",\"name\":\"Tips\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/category\\\/tips\\\/#listItem\",\"position\":2,\"name\":\"Tips\",\"item\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/category\\\/tips\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/2026\\\/08\\\/20\\\/consent-phishing\\\/#listItem\",\"name\":\"Consent Phishing: The Attack That Does Not Need Your Password\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/#listItem\",\"name\":\"Hogar\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/2026\\\/08\\\/20\\\/consent-phishing\\\/#listItem\",\"position\":3,\"name\":\"Consent Phishing: The Attack That Does Not Need Your Password\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/category\\\/tips\\\/#listItem\",\"name\":\"Tips\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/#organization\",\"name\":\"TRUST Lab\",\"description\":\"Sitio dedicado a la investigaci\\u00f3n, desarrollo y formaci\\u00f3n en ciberseguridad y tecnolog\\u00edas digitales avanzadas.\",\"url\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/trustlab.upct.es\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/TL-logo.png\",\"@id\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/2026\\\/08\\\/20\\\/consent-phishing\\\/#organizationLogo\",\"width\":201,\"height\":44},\"image\":{\"@id\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/2026\\\/08\\\/20\\\/consent-phishing\\\/#organizationLogo\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/author\\\/mdcano\\\/#author\",\"url\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/author\\\/mdcano\\\/\",\"name\":\"mdcano\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/2026\\\/08\\\/20\\\/consent-phishing\\\/#authorImage\",\"url\":\"https:\\\/\\\/trustlab.upct.es\\\/wp-content\\\/litespeed\\\/avatar\\\/6076032dbef8947839897d816a8acab1.jpg?ver=1787050854\",\"width\":96,\"height\":96,\"caption\":\"mdcano\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/2026\\\/08\\\/20\\\/consent-phishing\\\/#webpage\",\"url\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/2026\\\/08\\\/20\\\/consent-phishing\\\/\",\"name\":\"Consent Phishing: The Attack That Does Not Need Your Password - TRUST Lab\",\"description\":\"A legitimate sign-in page does not guarantee that an authorization request is safe. Learn how consent phishing can access your email, files or contacts without stealing your password.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/2026\\\/08\\\/20\\\/consent-phishing\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/author\\\/mdcano\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/author\\\/mdcano\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/trustlab.upct.es\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/phishing-consentimiento-oauth.jpg\",\"@id\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/2026\\\/08\\\/20\\\/consent-phishing\\\/#mainImage\",\"width\":1672,\"height\":941,\"caption\":\"Aplicaci\\u00f3n solicitando permisos de acceso a una cuenta mediante OAuth\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/2026\\\/08\\\/20\\\/consent-phishing\\\/#mainImage\"},\"datePublished\":\"2026-08-20T08:32:10+02:00\",\"dateModified\":\"2026-07-16T01:15:24+02:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/\",\"name\":\"TRUST Lab\",\"description\":\"Sitio dedicado a la investigaci\\u00f3n, desarrollo y formaci\\u00f3n en ciberseguridad y tecnolog\\u00edas digitales avanzadas.\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/trustlab.upct.es\\\/en\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Consent Phishing: The Attack That Does Not Need Your Password - TRUST Lab","description":"A legitimate sign-in page does not guarantee that an authorization request is safe. Learn how consent phishing can access your email, files or contacts without stealing your password.","canonical_url":"https:\/\/trustlab.upct.es\/en\/2026\/08\/20\/consent-phishing\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/trustlab.upct.es\/en\/2026\/08\/20\/consent-phishing\/#blogposting","name":"Consent Phishing: The Attack That Does Not Need Your Password - TRUST Lab","headline":"Consent Phishing: The Attack That Does Not Need Your Password","author":{"@id":"https:\/\/trustlab.upct.es\/en\/author\/mdcano\/#author"},"publisher":{"@id":"https:\/\/trustlab.upct.es\/en\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/trustlab.upct.es\/wp-content\/uploads\/2026\/08\/phishing-consentimiento-oauth.jpg","width":1672,"height":941,"caption":"Aplicaci\u00f3n solicitando permisos de acceso a una cuenta mediante OAuth"},"datePublished":"2026-08-20T08:32:10+02:00","dateModified":"2026-07-16T01:15:24+02:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/trustlab.upct.es\/en\/2026\/08\/20\/consent-phishing\/#webpage"},"isPartOf":{"@id":"https:\/\/trustlab.upct.es\/en\/2026\/08\/20\/consent-phishing\/#webpage"},"articleSection":"Tips, account security, connected applications, consent phishing, digital identity, identidad digital, OAuth, seguridad de cuentas, Opcional"},{"@type":"BreadcrumbList","@id":"https:\/\/trustlab.upct.es\/en\/2026\/08\/20\/consent-phishing\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/trustlab.upct.es\/en\/#listItem","position":1,"name":"Hogar","item":"https:\/\/trustlab.upct.es\/en\/","nextItem":{"@type":"ListItem","@id":"https:\/\/trustlab.upct.es\/en\/category\/tips\/#listItem","name":"Tips"}},{"@type":"ListItem","@id":"https:\/\/trustlab.upct.es\/en\/category\/tips\/#listItem","position":2,"name":"Tips","item":"https:\/\/trustlab.upct.es\/en\/category\/tips\/","nextItem":{"@type":"ListItem","@id":"https:\/\/trustlab.upct.es\/en\/2026\/08\/20\/consent-phishing\/#listItem","name":"Consent Phishing: The Attack That Does Not Need Your Password"},"previousItem":{"@type":"ListItem","@id":"https:\/\/trustlab.upct.es\/en\/#listItem","name":"Hogar"}},{"@type":"ListItem","@id":"https:\/\/trustlab.upct.es\/en\/2026\/08\/20\/consent-phishing\/#listItem","position":3,"name":"Consent Phishing: The Attack That Does Not Need Your Password","previousItem":{"@type":"ListItem","@id":"https:\/\/trustlab.upct.es\/en\/category\/tips\/#listItem","name":"Tips"}}]},{"@type":"Organization","@id":"https:\/\/trustlab.upct.es\/en\/#organization","name":"TRUST Lab","description":"Sitio dedicado a la investigaci\u00f3n, desarrollo y formaci\u00f3n en ciberseguridad y tecnolog\u00edas digitales avanzadas.","url":"https:\/\/trustlab.upct.es\/en\/","logo":{"@type":"ImageObject","url":"https:\/\/trustlab.upct.es\/wp-content\/uploads\/2024\/05\/TL-logo.png","@id":"https:\/\/trustlab.upct.es\/en\/2026\/08\/20\/consent-phishing\/#organizationLogo","width":201,"height":44},"image":{"@id":"https:\/\/trustlab.upct.es\/en\/2026\/08\/20\/consent-phishing\/#organizationLogo"}},{"@type":"Person","@id":"https:\/\/trustlab.upct.es\/en\/author\/mdcano\/#author","url":"https:\/\/trustlab.upct.es\/en\/author\/mdcano\/","name":"mdcano","image":{"@type":"ImageObject","@id":"https:\/\/trustlab.upct.es\/en\/2026\/08\/20\/consent-phishing\/#authorImage","url":"https:\/\/trustlab.upct.es\/wp-content\/litespeed\/avatar\/6076032dbef8947839897d816a8acab1.jpg?ver=1787050854","width":96,"height":96,"caption":"mdcano"}},{"@type":"WebPage","@id":"https:\/\/trustlab.upct.es\/en\/2026\/08\/20\/consent-phishing\/#webpage","url":"https:\/\/trustlab.upct.es\/en\/2026\/08\/20\/consent-phishing\/","name":"Consent Phishing: The Attack That Does Not Need Your Password - TRUST Lab","description":"A legitimate sign-in page does not guarantee that an authorization request is safe. Learn how consent phishing can access your email, files or contacts without stealing your password.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/trustlab.upct.es\/en\/#website"},"breadcrumb":{"@id":"https:\/\/trustlab.upct.es\/en\/2026\/08\/20\/consent-phishing\/#breadcrumblist"},"author":{"@id":"https:\/\/trustlab.upct.es\/en\/author\/mdcano\/#author"},"creator":{"@id":"https:\/\/trustlab.upct.es\/en\/author\/mdcano\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/trustlab.upct.es\/wp-content\/uploads\/2026\/08\/phishing-consentimiento-oauth.jpg","@id":"https:\/\/trustlab.upct.es\/en\/2026\/08\/20\/consent-phishing\/#mainImage","width":1672,"height":941,"caption":"Aplicaci\u00f3n solicitando permisos de acceso a una cuenta mediante OAuth"},"primaryImageOfPage":{"@id":"https:\/\/trustlab.upct.es\/en\/2026\/08\/20\/consent-phishing\/#mainImage"},"datePublished":"2026-08-20T08:32:10+02:00","dateModified":"2026-07-16T01:15:24+02:00"},{"@type":"WebSite","@id":"https:\/\/trustlab.upct.es\/en\/#website","url":"https:\/\/trustlab.upct.es\/en\/","name":"TRUST Lab","description":"Sitio dedicado a la investigaci\u00f3n, desarrollo y formaci\u00f3n en ciberseguridad y tecnolog\u00edas digitales avanzadas.","inLanguage":"en-US","publisher":{"@id":"https:\/\/trustlab.upct.es\/en\/#organization"}}]},"og:locale":"en_US","og:site_name":"TRUST Lab - Sitio dedicado a la investigaci\u00f3n, desarrollo y formaci\u00f3n en ciberseguridad y tecnolog\u00edas digitales avanzadas.","og:type":"article","og:title":"Consent Phishing: The Attack That Does Not Need Your Password - TRUST Lab","og:description":"A legitimate sign-in page does not guarantee that an authorization request is safe. Learn how consent phishing can access your email, files or contacts without stealing your password.","og:url":"https:\/\/trustlab.upct.es\/en\/2026\/08\/20\/consent-phishing\/","og:image":"https:\/\/trustlab.upct.es\/wp-content\/uploads\/2024\/05\/TL-logo.png","og:image:secure_url":"https:\/\/trustlab.upct.es\/wp-content\/uploads\/2024\/05\/TL-logo.png","article:published_time":"2026-08-20T06:32:10+00:00","article:modified_time":"2026-07-15T23:15:24+00:00","twitter:card":"summary_large_image","twitter:title":"Consent Phishing: The Attack That Does Not Need Your Password - TRUST Lab","twitter:description":"A legitimate sign-in page does not guarantee that an authorization request is safe. Learn how consent phishing can access your email, files or contacts without stealing your password.","twitter:image":"https:\/\/trustlab.upct.es\/wp-content\/uploads\/2024\/05\/TL-logo.png"},"aioseo_meta_data":{"post_id":"3837","title":null,"description":null,"keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"BlogPosting","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-07-15 23:14:34","updated":"2026-08-20 06:43:40","seo_analyzer_scan_date":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/trustlab.upct.es\/en\/\" title=\"Hogar\">Hogar<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/trustlab.upct.es\/en\/category\/tips\/\" title=\"Tips\">Tips<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tConsent Phishing: The Attack That Does Not Need Your Password\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Hogar","link":"https:\/\/trustlab.upct.es\/en\/"},{"label":"Tips","link":"https:\/\/trustlab.upct.es\/en\/category\/tips\/"},{"label":"Consent Phishing: The Attack That Does Not Need Your Password","link":"https:\/\/trustlab.upct.es\/en\/2026\/08\/20\/consent-phishing\/"}],"_links":{"self":[{"href":"https:\/\/trustlab.upct.es\/en\/wp-json\/wp\/v2\/posts\/3837","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustlab.upct.es\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/trustlab.upct.es\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/trustlab.upct.es\/en\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/trustlab.upct.es\/en\/wp-json\/wp\/v2\/comments?post=3837"}],"version-history":[{"count":2,"href":"https:\/\/trustlab.upct.es\/en\/wp-json\/wp\/v2\/posts\/3837\/revisions"}],"predecessor-version":[{"id":3839,"href":"https:\/\/trustlab.upct.es\/en\/wp-json\/wp\/v2\/posts\/3837\/revisions\/3839"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trustlab.upct.es\/en\/wp-json\/wp\/v2\/media\/3836"}],"wp:attachment":[{"href":"https:\/\/trustlab.upct.es\/en\/wp-json\/wp\/v2\/media?parent=3837"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/trustlab.upct.es\/en\/wp-json\/wp\/v2\/categories?post=3837"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/trustlab.upct.es\/en\/wp-json\/wp\/v2\/tags?post=3837"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}