Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ConsentFix: a new ClickFix variation for compromising Microsoft 365 accounts

0
Medium
Breach
Published: 07/21/2026 (07/21/2026, 15:28:43 UTC)
Source: Kaspersky Security Blog

Description

Discover how attackers use the ConsentFix attack to hijack Microsoft 365 sessions, what risks it poses to organizations, and how to protect your corporate infrastructure.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/21/2026, 15:34:46 UTC

Technical Analysis

ConsentFix is a newly identified variation of the ClickFix social engineering attack that compromises Microsoft 365 accounts by exploiting OAuth token granting processes. Attackers send phishing emails linking to fake file-sharing sites that prompt users to authenticate with their Microsoft 365 accounts and perform a sequence of browser actions, including dragging an OAuth token URL into a drop zone controlled by the attacker. This grants attackers access to the victim's Microsoft 365 session without requiring password theft or bypassing multi-factor authentication. The attack can expose corporate email, Teams, OneDrive, SharePoint, and other services depending on the organization's subscription and privileges. Publicly available attack blueprints and tutorials facilitate widespread adoption of this technique. Defenses include robust email gateway security and ongoing user training to recognize and resist social engineering tactics.

Potential Impact

Successful exploitation results in unauthorized access to Microsoft 365 accounts, allowing attackers to read and send corporate emails, access Teams communications, exfiltrate or tamper with documents on OneDrive and SharePoint, and potentially move laterally within the corporate network. This can lead to data breaches, business email compromise, internal phishing, malware deployment, and broader organizational compromise. The attack bypasses password theft and multi-factor authentication, increasing its effectiveness against standard security controls.

Defensive Guidance

No official patch is applicable as this is a social engineering attack exploiting OAuth flows. Organizations should deploy strong email gateway security solutions to reduce phishing email delivery. Regular cybersecurity awareness training is critical to educate employees about the ConsentFix technique and similar social engineering tactics. Blocking specific browser actions is insufficient due to attacker adaptability. Monitoring and restricting OAuth app permissions within Microsoft 365 can also help reduce risk. Organizations should incorporate this threat into their security awareness programs and incident response plans.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.kaspersky.com/blog/consentfix-microsoft-365-account-hijacking/56155/","fetched":true,"fetchedAt":"2026-07-21T15:34:37.955Z","wordCount":1230}
Classification
{"confidence":0.75,"severitySource":"default","classifier":"rss-v2"}

Threat ID: 6a5f918d2a4a8d5989579eda

Added to database: 07/21/2026, 15:34:37 UTC

Last enriched: 07/21/2026, 15:34:46 UTC

Last updated: 08/26/2026, 20:08:49 UTC

Views: 149

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses