Mirage2FA Campaign Compromises Over 4,500 Companies Using Microsoft 365 Exploit
A widespread phishing campaign known as Mirage2FA has compromised over 4,500 US and EU companies by exploiting Microsoft 365 login flows and bypassing two-factor authentication.
The commercial phishing-as-a-service toolkit, which has been active since 2024, targets legitimate login flows to steal passwords and session cookies. This allows attackers to gain access to authenticated Microsoft 365 sessions and connected services, creating significant identity-related risks for affected companies.
The campaign's broad geographic reach includes countries such as India, Singapore, the United Kingdom, Canada, Saudi Arabia, and South Africa. Technology, manufacturing, and education were among the most targeted industries.