Consent phishing
Consent phishing does not want your password. It wants you to say yes.
You are shown a genuine permission screen from a service you actually use, asking whether an app can read your email or your files. You approve it, because the screen is real and the request looks routine. Nothing has been stolen and nothing has been broken. The attacker now has legitimate access that a password change does not remove, because they never had the password. Undoing it means finding the app in your account settings and revoking it.
Checked against the primary source.
