Open banking makes it easy to connect budgeting tools, tax software, and investment dashboards to your bank or brokerage. But those same connections can be abused if someone tries to link a service to your accounts without your knowledge. This guide explains what a legitimate request looks like, how to spot red flags, and what to do immediately if you see a connection prompt you didn’t initiate.
What “Open Banking” Means in Practice
Open banking is a secure way for apps and websites to request access to certain financial data—like balances or transactions—through standardized connections. Instead of giving an app your username and password, you’re redirected to your bank or broker to approve a consent screen. If you approve, the app receives only the permissions you granted, such as “read transactions” or “initiate payments,” often for a limited time.
Common connection facilitators include well‑known aggregators and APIs used by personal‑finance tools, brokers, tax prep services, and payment apps. The goal is convenience and security—when you are the one initiating the request.
Where You’ll See Connection Requests
- During a new app signup when you choose “Connect my bank/broker.”
- Inside an existing app when you add another account or refresh a broken link.
- In your bank or broker portal under “Connected apps,” “Third‑party access,” “Security,” or “Linked accounts.”
- As an email, SMS, or push notification from your bank alerting you that a new connection was requested or approved.
Legitimate Requests vs. Suspicious Prompts
Signs of a legitimate consent screen
- Shows the exact app or company name you recognize and are currently using.
- Lists the specific permissions requested (e.g., read balances, read transactions, initiate payments/ACH).
- Displays the accounts involved (e.g., checking ending in 1234) and, sometimes, the data types (e.g., 24 months of transactions).
- Appears in the middle of your intentional action (you just clicked “Connect bank”).
- Includes a clear expiration or review period and a link to manage or revoke later.
Red flags that suggest you didn’t initiate the request
- You weren’t signing up for or linking any app when the prompt appeared.
- The app name looks generic, mismatched, or misspelled (e.g., “Budgeter Pro Inc” vs. “BudgetPro”).
- Permissions are too broad for the claimed purpose (e.g., a read‑only budgeting app asking for payment initiation).
- It’s a “connection renewed” prompt from an app you don’t use.
- You receive an unexpected bank email or SMS about a new connection you don’t recognize.
- The consent screen omits details like which accounts will be shared.
Why Unauthorized Requests Happen
- Credential stuffing or phishing: An attacker who harvested login details tries to connect an app to siphon data or set up transfers.
- Account recovery abuse: Someone who can intercept your email or SMS may push connection prompts during password resets.
- Malicious or shady apps: Low‑reputation apps request excessive permissions and quietly re‑connect later.
- Old connections lingering: A service you once tried may attempt to refresh access after policy or API changes.
Immediate Actions If You See a Request You Didn’t Start
- Do not approve. Close the prompt and stop any ongoing sign‑in flow.
- Log in directly to your bank or broker (using a trusted bookmark or typing the URL) and review:
- Connected apps / Third‑party access
- Recent login history
- Security and alerts settings
- Revoke unfamiliar access to any app you do not recognize or no longer use.
- Change your password and ensure it’s unique and strong. Update your password manager record.
- Turn on or tighten MFA (preferably a hardware security key or an authenticator app, not SMS if you can avoid it).
- Check recent transactions and transfers across all linked accounts.
- Contact your bank or broker’s fraud team if anything looks off or if you suspect account compromise.
How to Review and Clean Up Existing Connections
Make a quick audit part of your regular financial hygiene. Most banks and brokers provide a dashboard for connected services. Remove anything outdated or excessive.
What to keep vs. remove
- Keep: Tools you actively use and trust, requesting appropriate, minimal permissions.
- Remove: Apps you no longer use, don’t recognize, or that request payment initiation when you only need read access.
Permissions to look for
- Read‑only access: Balances, transactions, holdings—appropriate for budgeting, tax prep, or portfolio tracking.
- Write/transfer access: Payment initiation, ACH, or trading permissions—only grant if you specifically need the function and fully trust the provider.
Verification Checks Before You Approve Any New Connection
- Match the names: Confirm the app name and developer exactly match what you installed from a reputable app store or website.
- Check the purpose vs. permissions: If it’s a budgeting app, it shouldn’t need payment initiation or trading access.
- Time and context: Are you in the middle of linking? If not, treat it as suspicious.
- Use out‑of‑band confirmation: If the request mentions a company you use, log in to that company’s site directly and verify they’re asking you to connect now.
- Search the provider’s support pages: Reputable services document what data they request and how connections appear.
- Look for secure session indicators: Ensure you’re on your bank’s real domain (no look‑alike URLs) and the connection window is not a spoofed overlay.
Protective Settings to Enable at Your Bank or Broker
- Security alerts: Turn on notifications for new device logins, password changes, and new third‑party connections.
- Stronger MFA: Prefer hardware security keys or app‑based codes over SMS where supported.
- Session controls: Periodically sign out other sessions and remove old devices.
- Spending and transfer controls: Set daily transfer limits, approval requirements, or hold periods for new payees.
- Nickname and hide accounts: Label accounts to spot unfamiliar activity and hide ones you rarely use from quick‑link screens.
If You Accidentally Approved a Suspicious Connection
- Revoke access immediately from your bank/broker’s connected‑apps page.
- Change your password and rotate your MFA method (e.g., new authenticator seed or new security key where possible).
- Review transactions, transfers, and orders for unauthorized activity and dispute anything suspicious promptly.
- Monitor other financial accounts that may share the same email or recovery phone.
- File a fraud report with your institution and request additional monitoring or a temporary hold if needed.
How This Fits Into Your Broader Privacy Strategy
Open‑banking connections reveal sensitive patterns—income, spending categories, locations, and merchant relationships. Limiting third‑party access reduces your exposure if a connected app is breached or changes ownership. Combine connection hygiene with the basics:
- Unique passwords and a password manager for every financial account.
- Phishing resistance: Never approve a connection or MFA prompt you didn’t trigger, and don’t click “security alert” links—go to the site directly.
- Data minimization: Only share what’s essential; prefer read‑only scopes when possible.
- Regular reviews: Calendar a quarterly check of connected apps, alerts, and permissions.
When Credit and Identity Monitoring Helps
Unauthorized bank connections can be part of a larger pattern of identity misuse—new credit inquiries, account openings, or billing address changes. Ongoing monitoring can alert you to these events quickly so you can respond before damage spreads. If you want a single place to watch your credit, identity‑related alerts, and financial changes, consider a dedicated monitoring service. You can learn more here: SmartCredit for privacy, credit monitoring, and identity protection.
Practical Checklist: Before, During, and After a Request
Before
- Decide if the app truly needs financial access. If yes, choose read‑only when possible.
- Confirm the app’s exact name, website, and developer.
- Turn on bank alerts for third‑party access changes.
During
- Verify the bank domain and the app name on the consent screen.
- Read permissions line by line; deselect accounts you don’t need to share.
- Approve only if timing, purpose, and scope match your intent.
After
- Visit your bank’s “Connected apps” page to confirm the right permissions were applied.
- Document the connection date and scope in case you need to audit later.
- Set a reminder to re‑review in 90 days.
Frequently Asked Questions
Is every “new connection” alert a sign of fraud?
No. Some apps periodically refresh connections or migrate to a new method and will prompt you to re‑approve. Still, you should verify the timing and the app’s identity before approving.
Can a third‑party app move money without my consent?
Only if you explicitly granted payment or transfer permissions. Many budgeting or portfolio apps request read‑only access. Always check the scopes during consent.
What if I can’t tell which app is behind the request?
Deny the request, log in to your bank directly, review the connected‑apps list, and contact support. Do not approve until you can verify the requesting party.
Do I need to delete my bank account if I approved something suspicious?
No. Revoke the connection, change your password, rotate MFA, and monitor activity. Work with your bank’s fraud team if you notice anything unauthorized.
Conclusion
Open banking can be safe and convenient when you’re the one initiating the connection and you limit access to only what’s necessary. Treat unexpected consent prompts as potential warnings, verify the app’s identity and requested permissions, and regularly prune your connected‑apps list. By combining strong authentication, real‑time alerts, and periodic reviews, you’ll spot unauthorized requests early and keep your financial identity under your control.
Good to Know
Legitimate open-banking requests typically show the exact app name, a time stamp, and the specific account permissions requested. Vague names, blank logos, or overly broad permissions are strong reasons to deny and investigate.