First Midwest BankFirst Midwest Bank logoArrow DownIcon of an arrow pointing downwardsArrow LeftIcon of an arrow pointing to the leftArrow RightIcon of an arrow pointing to the rightArrow UpIcon of an arrow pointing upwardsBank IconIcon of a bank buildingCheck IconIcon of a bank checkCheckmark IconIcon of a checkmarkCredit-Card IconIcon of a credit-cardFunds IconIcon of hands holding a bag of moneyAlert IconIcon of an exclaimation markIdea IconIcon of a bright light bulbKey IconIcon of a keyLock IconIcon of a padlockMail IconIcon of an envelopeMobile Banking IconIcon of a mobile phone with a dollar sign in a speech bubbleMoney in Home IconIcon of a dollar sign inside of a housePhone IconIcon of a phone handsetPlanning IconIcon of a compassReload IconIcon of two arrows pointing head to tail in a circleSearch IconIcon of a magnifying glassFacebook IconIcon of the Facebook logoLinkedIn IconIcon of the LinkedIn LogoXX Symbol, typically used to close a menu
Skip to nav Skip to content
FDIC-Insured - Backed by the full faith and credit of the U.S. Government

Consent Phishing: A ‘Trusted’ Growing Threat to Email, Messaging and Financial Security

Cybercriminals are increasingly using a sophisticated scam called “OAuth” or “consent phishing,” which convinces users to grant permission to a malicious application to gain access to victims' email, text and direct message accounts, and other sensitive information -- without ever stealing a password.

The FBI recently warned that these ever-increasing attacks appear to come from trusted sources, including government officials, media contacts, event coordinators, or other familiar organizations.1

No password needed to access your information

Unlike traditional phishing attacks that attempt to capture usernames and passwords, consent phishing tricks users into approving access for malicious intent. Victims may receive what appears to be a file-sharing request, document to electronically sign, event invitation, or identity verification message. When they click the link, they are directed to a legitimate Microsoft or Google authorization screen and asked to approve access for an application controlled by the attacker.1,2

Because the authorization request comes through a trusted platform, many users assume it is safe. However, selecting “Allow” can give attackers ongoing access to emails, files, contacts, and other sensitive information. Simply changing a password does not remove the access that has been granted to the malicious application.1

For bank clients, the risks are significant. Email accounts often contain financial alerts, account notifications, password-reset links, tax documents, and other personal information. A compromised email account can provide criminals with valuable information that may be used for fraud or identity theft.2

Look for the warning signs

  • Unexpected file-sharing requests, e-sign documents, invitations, or identity verification messages.
  • Messages from unfamiliar contacts or organizations requesting urgent action.
  • Permission requests for applications you do not recognize.
  • Requests asking you to click “Allow” to view a document or verify your identity.
  • Communications that create urgency or pressure you to act quickly.
  • Application permission screens requesting broad access to email, files, or contacts.

To protect yourself, carefully review permission requests before approving them, verify the identity of anyone requesting access through a separate communication channel, and periodically review authorized applications connected to your email accounts.1,2

Old National Bank’s Commitment to Fraud Prevention

At Old National, protecting clients from fraud is a constant focus and a top priority. Through fraud monitoring, educational resources, security awareness initiatives, and ongoing client outreach, we work hard to help individuals recognize evolving scams and safeguard their finances.

We encourage you to take a few minutes to learn about emerging threats and review the fraud-prevention resources available here on oldnational.com. Getting better informed is the best decision you can make today to protect your personal information and your financial well-being.

  1. Federal Bureau of Investigation (FBI), Public Service Announcement: Malicious Cyber Actors Gain Access to Victim Accounts Through Consent Phishing, September 2026.
  1. Cybersecurity Girl Newsletter, summary of FBI warning regarding OAuth consent phishing and persistent account access risks, 2026.

Subscribe for Insights

Subscribe