Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

Summary

The Mirage2FA campaign has impacted over 4,500 US and EU companies by exploiting Microsoft 365 login flows to bypass two-factor authentication. This phishing-as-a-service toolkit has been active from 2024 to 2026, with research indicating that nearly half of targeted email addresses may have been compromised.

IFF Assessment

FOE

The Mirage2FA campaign's success in bypassing multi-factor authentication and compromising a significant number of accounts poses a serious threat to defenders.

Defender Context

This campaign highlights the persistent threat of sophisticated phishing attacks that can circumvent multi-factor authentication by abusing legitimate login flows. Defenders should be vigilant about monitoring for unusual login patterns and user reports of suspicious authentication requests, especially in environments heavily reliant on Microsoft 365.

Read Full Story →