Filed under: Cybersecurity · Phishing · July 2026
What happened
Attackers have refined a trick called “ConsentFix,” an evolution of the “ClickFix” scam, that steals Microsoft 365 accounts without ever grabbing a password. The victim gets a real-looking Microsoft sign-in screen and is coached to drag a small “localhost” link into their browser, which quietly hands the attacker a live session token. Because the token is already an approved, signed-in session, it sails right past the account password and multi-factor authentication (MFA). Step-by-step instructions, working code, and video tutorials for this attack were posted to Russian cybercrime forums back in March, so it is no longer limited to skilled hackers.
Why it matters to your business
For most Phoenix small businesses, the Microsoft 365 mailbox is the crown jewels — it holds invoices, banking details, client files, and the password-reset links for everything else. Attackers scout targets on LinkedIn first, then send a tailored lure through trusted services like Dropbox or DocSend, so the message looks routine. One employee dragging one link can give a stranger full access to email, and MFA won’t save you because it was never challenged. From there it’s a short step to fake invoices, wire-transfer fraud, and messages sent to your clients in your own name.
What to do this week
Lock down who can approve apps: in the Microsoft Entra admin center (entra.microsoft.com), go to Identity → Applications → Enterprise applications → Consent and permissions → User consent settings, and set it to “Do not allow user consent” (or allow only verified publishers with low-impact permissions). Turn on the admin consent workflow on that same screen so approval requests route to you instead. Then tell your team the plain rule: Microsoft never asks you to drag or paste a link into your browser bar to log in — if a sign-in prompt does, stop and report it. Finally, in the Entra sign-in logs, spot-check for logins from unexpected cities or countries over the past two weeks.
The bigger picture
MFA is essential, but it is no longer a finish line — today’s attacks skip the password fight entirely and go after the human and the session token. Training your team to recognize the lure is now just as important as the technical controls behind it. → Phishing Attacks: Why SMBs Are Prime Targets and How to Fight Back
Not sure whether your Microsoft 365 is set up to block this? Book a free consult — https://micro1tech.com/contact/