Malicious Cyber Actors Gain Access to Victim Accounts Through Consent Phishing
Scammers trick you into giving them permission to access your online accounts by pretending to be a trusted service. Once you grant access, they take over your accounts and steal your data or money.
How it works
You receive an email, text, or pop-up that looks like it comes from a service you use (like your bank or email provider). The message says you need to grant permission or confirm access to keep your account secure. When you click and approve, the scammer gets legitimate access to your account without needing your password. They then change your settings, drain money, steal information, or lock you out.
Red flags to watch for
- Message creates urgency: your account is at risk or access will be lost
- Link goes to a login page that looks official but feels slightly off
- You are asked to approve access for an unfamiliar app or service
- Real companies do not ask you to grant permissions via unsolicited messages
- Permission request appears after you click a suspicious link
What to do
Do not click links or approve access requests in unsolicited emails or texts, even if they look official. Instead, go directly to the website by typing the address yourself in your browser, log in, and check your account settings to see if anything unusual happened. If you already granted access, change your password immediately, review connected apps and remove any you do not recognize, and contact the company's support line directly using the number on their website.
If this reached you
Source: FBI IC3 . Scam Sentinel summarizes official guidance in plain language; it is a decision aid, not a guarantee.