Cybersecurity Awareness: Hidden Access Paths - Application Access

When most people think about account security, they think about credentials such as passwords and multi-factor authentication (MFA).
However, there are other hidden ways that your accounts and data can be accessed, without needing your credentials.
In this awareness post, we look at how attackers can misuse one of these hidden access paths: application access.
Quick Takeaway
Section | Key Message |
What it is | Applications can be granted permission to access data or services on your behalf. |
Why it matters | Malicious applications can be used by attackers to steal or compromise your data. |
What to do | Always PAUSE and review application consent requests, paying particular attention to WHO is requesting access and WHAT permissions are being requested. |
What not to do | Never approve application access without understanding its purpose. |
What It Is
Many modern applications allow you to connect to other applications and services. This enables them to share data and perform actions on your behalf.
For example:
Signing into an application using your Google or Microsoft account
Connecting an AI tool to your email, calendar, files, or contacts
Behind the scenes, there are technologies that allow these applications and services to communicate with each other, without requiring you to approve an action or sign in each time.
These integrations are typically set up using a consent prompt, asking you to approve the permissions being requested. Once permission is granted, the application may continue to access the approved services and data until that access is removed.

Why It Matters
These integrations are often legitimate and useful. However, they can also create opportunities for malicious access if granted to the wrong application.
Attackers may attempt to trick you into approving a malicious application that gives them access to your account and data without needing to obtain your credentials.
Because these connections can operate in the background, access may continue without you realising it. Therefore, it is important to understand the purpose of any application you approve, who published it, and the permissions being requested. The permissions requested are particularly important because applications with greater access can also create greater risk.
What To Do
PAUSE and review the consent request:
Who is requesting access? Identify the application, vendor, or service requesting access.
What permissions are being requested? The data or services the application wants to access.
Only approve access that is expected and necessary.
Review connected applications periodically.
Remove applications you no longer use or recognise.
What Not To Do
Never approve an application consent request that you did not expect or do not recognise.
If a request is unexpected, suspicious, or asks for excessive permissions, deny it and, where appropriate, report it using the available official reporting channels.

