ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds
Security researchers reveal new phishing tactics targeting Microsoft 365 accounts.
📍 Aftermath
The ARToken phishing panel and EvilTokens device-code phishing kit were used to target Microsoft 365 accounts. ConsentFix and ClickFix were identified as methods for hijacking these accounts.
The story quieted without a definitive conclusion in the coverage.
Epilogue added 20d ago, after coverage quieted.
Questions people are asking
What are ConsentFix and ClickFix?
ConsentFix and ClickFix are phishing techniques used to hijack Microsoft 365 accounts quickly.
Which phishing tools are mentioned in the coverage?
The ARToken phishing panel and the EvilTokens device-code phishing kit are mentioned.
Which outlets are covering this trend?
Help Net Security, The Register, Cisco Talos Blog, and BleepingComputer are covering this trend.
What happened
Security researchers have identified new phishing techniques, ConsentFix and ClickFix, that can hijack Microsoft 365 accounts in as little as three seconds. These methods exploit device-code phishing to gain unauthorized access.
Coverage from Help Net Security, The Register, Cisco Talos Blog, and BleepingComputer highlights the use of the ARToken phishing panel and the EvilTokens device-code phishing kit. The reports detail how these tools are used by cybercriminals to target Microsoft 365 accounts.
Watch for further details on how these phishing techniques operate and any potential responses from Microsoft. Coverage does not yet specify any official statements from Microsoft.
Synthesized by Archynetys from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 25d ago.
Sources (4)
- The ARToken phishing panel targets Microsoft 365 accounts Help Net Security · 26d ago
- EvilTokens device-code phishing kit totally more evil than we all thought The Register · 26d ago
- ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365 Cisco Talos Blog · 26d ago
- ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds BleepingComputer · 26d ago
How fast it spread
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
Topics
Related trends
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
A fake Microsoft Teams update fuels a massive phishing surge, exposing corporate PCs to remote‑access malware.
Hugging Face wants $100mn of compute from OpenAI
Hugging Face seeks $100 million in OpenAI compute amid fresh cyber‑attack concerns
Ariana Grande Sues Over Yearslong Hacking Campaign Targeting Inner Circle
Ariana Grande has initiated legal action against alleged hackers following a multi-year campaign targeting her inner circle and unreleased creative assets.
Microsoft launches its first cybersecurity model, plus a new agentic cybersecurity system
Microsoft is challenging industry leaders with a new in-house cybersecurity AI model and an agentic system designed to reduce costs.
Apple Releases iOS 26.6 and iPadOS 26.6 With iOS 27 Optimizations
Apple has launched iOS 26.6, iPadOS 26.6, and macOS Tahoe 26.6, focusing on extensive security patches and preparation for version 27.
Microsoft Unveils A.I. Cybersecurity Tools
Microsoft's debut AI-driven cybersecurity suite signals a rapid shift toward autonomous threat defense.