


Perceptive Security
SOC/SIEM Consultancy

ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds
Published:
2 juli 2026 om 14:00:10
Alert date:
2 juli 2026 om 15:02:30
Source:
bleepingcomputer.com
Identity & Access, Web Technologies, Enterprise Applications
ConsentFix and ClickFix are attack techniques targeting Microsoft 365 accounts by stealing authentication tokens within seconds. The attacks leverage fake prompts and malicious OAuth flows to bypass multi-factor authentication (MFA). By exploiting user consent mechanisms and ClickFix-style social engineering, attackers can gain unauthorized access to M365 accounts without needing credentials. These methods are particularly dangerous because they circumvent traditional MFA protections. The article outlines how these tactics work technically and provides guidance on defensive measures organizations can take to protect their Microsoft 365 environments.
Technical details
Mitigation steps:
Affected products:
Microsoft 365
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
