ConsentFix: a new ClickFix variation for compromising Microsoft 365 accounts
Discover how attackers use the ConsentFix attack to hijack Microsoft 365 sessions, what risks it poses to organizations, and how to protect your corporate infrastructure.
AI Analysis
Technical Summary
ConsentFix is a newly identified variation of the ClickFix social engineering attack that compromises Microsoft 365 accounts by exploiting OAuth token granting processes. Attackers send phishing emails linking to fake file-sharing sites that prompt users to authenticate with their Microsoft 365 accounts and perform a sequence of browser actions, including dragging an OAuth token URL into a drop zone controlled by the attacker. This grants attackers access to the victim's Microsoft 365 session without requiring password theft or bypassing multi-factor authentication. The attack can expose corporate email, Teams, OneDrive, SharePoint, and other services depending on the organization's subscription and privileges. Publicly available attack blueprints and tutorials facilitate widespread adoption of this technique. Defenses include robust email gateway security and ongoing user training to recognize and resist social engineering tactics.
Potential Impact
Successful exploitation results in unauthorized access to Microsoft 365 accounts, allowing attackers to read and send corporate emails, access Teams communications, exfiltrate or tamper with documents on OneDrive and SharePoint, and potentially move laterally within the corporate network. This can lead to data breaches, business email compromise, internal phishing, malware deployment, and broader organizational compromise. The attack bypasses password theft and multi-factor authentication, increasing its effectiveness against standard security controls.
Mitigation Recommendations
No official patch is applicable as this is a social engineering attack exploiting OAuth flows. Organizations should deploy strong email gateway security solutions to reduce phishing email delivery. Regular cybersecurity awareness training is critical to educate employees about the ConsentFix technique and similar social engineering tactics. Blocking specific browser actions is insufficient due to attacker adaptability. Monitoring and restricting OAuth app permissions within Microsoft 365 can also help reduce risk. Organizations should incorporate this threat into their security awareness programs and incident response plans.
ConsentFix: a new ClickFix variation for compromising Microsoft 365 accounts
Description
Discover how attackers use the ConsentFix attack to hijack Microsoft 365 sessions, what risks it poses to organizations, and how to protect your corporate infrastructure.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
ConsentFix is a newly identified variation of the ClickFix social engineering attack that compromises Microsoft 365 accounts by exploiting OAuth token granting processes. Attackers send phishing emails linking to fake file-sharing sites that prompt users to authenticate with their Microsoft 365 accounts and perform a sequence of browser actions, including dragging an OAuth token URL into a drop zone controlled by the attacker. This grants attackers access to the victim's Microsoft 365 session without requiring password theft or bypassing multi-factor authentication. The attack can expose corporate email, Teams, OneDrive, SharePoint, and other services depending on the organization's subscription and privileges. Publicly available attack blueprints and tutorials facilitate widespread adoption of this technique. Defenses include robust email gateway security and ongoing user training to recognize and resist social engineering tactics.
Potential Impact
Successful exploitation results in unauthorized access to Microsoft 365 accounts, allowing attackers to read and send corporate emails, access Teams communications, exfiltrate or tamper with documents on OneDrive and SharePoint, and potentially move laterally within the corporate network. This can lead to data breaches, business email compromise, internal phishing, malware deployment, and broader organizational compromise. The attack bypasses password theft and multi-factor authentication, increasing its effectiveness against standard security controls.
Defensive Guidance
No official patch is applicable as this is a social engineering attack exploiting OAuth flows. Organizations should deploy strong email gateway security solutions to reduce phishing email delivery. Regular cybersecurity awareness training is critical to educate employees about the ConsentFix technique and similar social engineering tactics. Blocking specific browser actions is insufficient due to attacker adaptability. Monitoring and restricting OAuth app permissions within Microsoft 365 can also help reduce risk. Organizations should incorporate this threat into their security awareness programs and incident response plans.
Technical Details
- Article Source
- {"url":"https://www.kaspersky.com/blog/consentfix-microsoft-365-account-hijacking/56155/","fetched":true,"fetchedAt":"2026-07-21T15:34:37.955Z","wordCount":1230}
- Classification
- {"confidence":0.75,"severitySource":"default","classifier":"rss-v2"}
Threat ID: 6a5f918d2a4a8d5989579eda
Added to database: 07/21/2026, 15:34:37 UTC
Last enriched: 07/21/2026, 15:34:46 UTC
Last updated: 08/26/2026, 20:08:49 UTC
Views: 149
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.