Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

ConsentFix: a new ClickFix variation for compromising Microsoft 365 accounts

0
Medium
Vulnerability
Published: 07/21/2026 (07/21/2026, 15:28:43 UTC)
Source: Kaspersky Security Blog

Description

ConsentFix is a new social engineering attack variant targeting Microsoft 365 accounts by tricking users into granting OAuth access tokens to attackers. The attack involves convincing users to authenticate and perform specific browser actions that leak session tokens, enabling attackers to access corporate email, documents, and cloud services without stealing passwords. This technique bypasses multi-factor authentication and can lead to significant data exposure and lateral movement within corporate environments. The attack is facilitated by phishing emails linking to fake file-sharing sites and detailed public guides that lower the barrier for attackers. Organizations face risks including compromised email, phishing from legitimate accounts, data exfiltration, and malware uploads. Mitigations focus on mail gateway security and employee awareness training. No specific software versions are affected as this targets user behavior and OAuth flows rather than a software vulnerability.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/21/2026, 15:34:46 UTC

Technical Analysis

ConsentFix is a newly identified variation of the ClickFix social engineering attack that compromises Microsoft 365 accounts by exploiting OAuth token granting processes. Attackers send phishing emails linking to fake file-sharing sites that prompt users to authenticate with their Microsoft 365 accounts and perform a sequence of browser actions, including dragging an OAuth token URL into a drop zone controlled by the attacker. This grants attackers access to the victim's Microsoft 365 session without requiring password theft or bypassing multi-factor authentication. The attack can expose corporate email, Teams, OneDrive, SharePoint, and other services depending on the organization's subscription and privileges. Publicly available attack blueprints and tutorials facilitate widespread adoption of this technique. Defenses include robust email gateway security and ongoing user training to recognize and resist social engineering tactics.

Potential Impact

Successful exploitation results in unauthorized access to Microsoft 365 accounts, allowing attackers to read and send corporate emails, access Teams communications, exfiltrate or tamper with documents on OneDrive and SharePoint, and potentially move laterally within the corporate network. This can lead to data breaches, business email compromise, internal phishing, malware deployment, and broader organizational compromise. The attack bypasses password theft and multi-factor authentication, increasing its effectiveness against standard security controls.

Mitigation Recommendations

No official patch is applicable as this is a social engineering attack exploiting OAuth flows. Organizations should deploy strong email gateway security solutions to reduce phishing email delivery. Regular cybersecurity awareness training is critical to educate employees about the ConsentFix technique and similar social engineering tactics. Blocking specific browser actions is insufficient due to attacker adaptability. Monitoring and restricting OAuth app permissions within Microsoft 365 can also help reduce risk. Organizations should incorporate this threat into their security awareness programs and incident response plans.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Article Source
{"url":"https://www.kaspersky.com/blog/consentfix-microsoft-365-account-hijacking/56155/","fetched":true,"fetchedAt":"2026-07-21T15:34:37.955Z","wordCount":1230}

Threat ID: 6a5f918d2a4a8d5989579eda

Added to database: 07/21/2026, 15:34:37 UTC

Last enriched: 07/21/2026, 15:34:46 UTC

Last updated: 07/21/2026, 16:51:40 UTC

Views: 18

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses