Cybercriminals are now using a new phishing method called ConsentFix, which builds on the well-known ClickFix technique to take over Microsoft 365 accounts within seconds. Instead of breaking into systems through software flaws, attackers trick users into completing what looks like a normal verification step. Everything appears legitimate, making the attack much harder to recognize. The technique targets user trust rather than technical weaknesses.

microsoft-365-consentfix-phishing-attack

ClickFix attacks work by displaying fake verification or security prompts that ask users to perform simple actions, such as pressing keyboard shortcuts or following on-screen instructions. Those actions secretly execute attacker-controlled commands on the victim’s own device. Since users believe they are completing a routine security check, they unknowingly help the attacker gain access. No software vulnerability is required for the attack to succeed.

ConsentFix is a more advanced version that shifts the focus from running commands to stealing Microsoft 365 authentication sessions. Victims receive phishing messages, often delivered through trusted file-sharing services, leading them to what appears to be a genuine Microsoft sign-in page. During the login process, they are instructed to drag a special link into the browser. That single action allows attackers to capture valuable authentication information.

consentfix-cyberattack-microsoft-365-hacker

Unlike traditional phishing attacks, ConsentFix does not ask victims to enter passwords into fake websites. Instead, users complete a real Microsoft authentication process, but attackers steal the OAuth authorization data generated during the session. This allows criminals to obtain access and refresh tokens that can be used to enter Microsoft 365 services. As a result, attackers gain access without knowing the user’s password.

Because the authentication process itself is legitimate, even strong security measures such as multi-factor authentication may not stop the attack once the authorization tokens have been issued. The attacker simply reuses the stolen tokens to access email, cloud files, and other Microsoft 365 resources. From the user’s perspective, everything appears normal, making the compromise extremely difficult to detect in its early stages.

fake-captcha-consentfix-phishing-verification

Security researchers explain that these attacks are successful because they take advantage of habits people have developed over time. Most users quickly accept prompts, solve CAPTCHAs, approve sign-in requests, or follow browser instructions without carefully checking every step. Attackers carefully design fake instructions to match these familiar actions, increasing the chances that victims will complete them without suspicion.

Organizations can reduce the risk by training employees to question unexpected verification requests, especially those involving dragging links, copying browser content, or following unusual sign-in instructions. Security teams should also monitor OAuth activity, review authentication logs regularly, apply Conditional Access policies where possible, and restrict unnecessary access to high-risk Microsoft applications. Detecting suspicious token activity is becoming just as important as protecting passwords.

microsoft-365-oauth-token-security-consentfix

The rise of ConsentFix shows how cybercriminals are changing their tactics from stealing passwords to stealing authenticated sessions. Rather than attacking security technologies directly, they manipulate normal user behavior during trusted sign-in processes. As Microsoft 365 remains one of the world’s most widely used cloud platforms, organizations and users must stay alert, carefully verify every authentication step, and remember that even a three-second action can lead to a complete account takeover.

Stay alert, and keep your security measures updated!

Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news