CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 10

As cited

Copy frozen at (site build).

identity access

ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds

Microsoft 365 accounts can be compromised through ConsentFix and ClickFix attacks, which exploit fake authentication prompts and OAuth flows to steal tokens within seconds. These techniques bypass multi-factor authentication (MFA) by deceiving users into granting unauthorized consent. Organizations can implement defensive measures to mitigate this OAuth-based hijacking vector.

Why it matters: Practitioners should review OAuth app permission policies and user awareness training, as these attacks defeat MFA and provide rapid account compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

identity access

ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds

ConsentFix and ClickFix attacks compromise Microsoft 365 accounts by exploiting fake authentication prompts and OAuth flows to steal tokens within seconds, bypassing multifactor authentication. The attacks use social engineering to trick users into granting token access through malicious consent dialogs.

Why it matters: Microsoft 365 users and administrators need to recognize these token-theft tactics and enforce conditional access policies, app permission reviews, and security awareness training to prevent account compromise regardless of MFA status.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

identity access

ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds

ConsentFix and ClickFix attacks compromise Microsoft 365 accounts by exploiting fake authentication prompts and OAuth flows to steal tokens within seconds, bypassing multifactor authentication. The attacks use social engineering to trick users into granting token access through malicious consent dialogs.

Why it matters: Microsoft 365 users and administrators need to recognize these token-theft tactics and enforce conditional access policies, app permission reviews, and security awareness training to prevent account compromise regardless of MFA status.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary