Consent Phishing: A ‘Trusted’ Growing Threat to Email, Messaging and Financial Security
Cybercriminals are increasingly using a sophisticated scam called “OAuth” or “consent phishing,” which convinces users to grant permission to a malicious application to gain access to victims' email, text and direct message accounts, and other sensitive information -- without ever stealing a password.
The FBI recently warned that these ever-increasing attacks appear to come from trusted sources, including government officials, media contacts, event coordinators, or other familiar organizations.1
No password needed to access your information
Unlike traditional phishing attacks that attempt to capture usernames and passwords, consent phishing tricks users into approving access for malicious intent. Victims may receive what appears to be a file-sharing request, document to electronically sign, event invitation, or identity verification message. When they click the link, they are directed to a legitimate Microsoft or Google authorization screen and asked to approve access for an application controlled by the attacker.1,2
Because the authorization request comes through a trusted platform, many users assume it is safe. However, selecting “Allow” can give attackers ongoing access to emails, files, contacts, and other sensitive information. Simply changing a password does not remove the access that has been granted to the malicious application.1
For bank clients, the risks are significant. Email accounts often contain financial alerts, account notifications, password-reset links, tax documents, and other personal information. A compromised email account can provide criminals with valuable information that may be used for fraud or identity theft.2
Look for the warning signs
- Unexpected file-sharing requests, e-sign documents, invitations, or identity verification messages.
- Messages from unfamiliar contacts or organizations requesting urgent action.
- Permission requests for applications you do not recognize.
- Requests asking you to click “Allow” to view a document or verify your identity.
- Communications that create urgency or pressure you to act quickly.
- Application permission screens requesting broad access to email, files, or contacts.
To protect yourself, carefully review permission requests before approving them, verify the identity of anyone requesting access through a separate communication channel, and periodically review authorized applications connected to your email accounts.1,2
Old National Bank’s Commitment to Fraud Prevention
At Old National, protecting clients from fraud is a constant focus and a top priority. Through fraud monitoring, educational resources, security awareness initiatives, and ongoing client outreach, we work hard to help individuals recognize evolving scams and safeguard their finances.
We encourage you to take a few minutes to learn about emerging threats and review the fraud-prevention resources available here on oldnational.com. Getting better informed is the best decision you can make today to protect your personal information and your financial well-being.
- Federal Bureau of Investigation (FBI), Public Service Announcement: Malicious Cyber Actors Gain Access to Victim Accounts Through Consent Phishing, September 2026.
- Cybersecurity Girl Newsletter, summary of FBI warning regarding OAuth consent phishing and persistent account access risks, 2026.