mimile
Back to feed

Mirage2FA phishing campaign hits 4,500 companies, bypasses Microsoft 365 2FA

AI digest

This digest was compiled by AI from multiple sources — links to the originals are below.

Mirage2FA phishing campaign hits 4,500 companies, bypasses Microsoft 365 2FA

The Mirage2FA phishing-as-a-service campaign has targeted 4,532 organization email domains across the US and EU from 2024 to 2026. ANY.RUN research found 48% of targeted email addresses were potentially compromised, with 63.7% of victims in the United States. The campaign abuses legitimate Microsoft 365 login flows to bypass two-factor authentication and steal session cookies.

Key Facts

  • The Mirage2FA campaign targeted 4,532 unique organization email domains from 2024 to 2026.
  • ANY.RUN research found 48% of targeted email addresses were potentially compromised.
  • The United States accounted for 63.7% of total victims, with activity also observed in India, Singapore, the UK, Canada, Saudi Arabia, and South Africa.
  • ANY.RUN uncovered more than 9,000 potential compromise events involving cookie and password theft, SSO logins, and 2FA bypass.
  • Technology, manufacturing, and education were among the most targeted industries.

Campaign Scope

The Mirage2FA campaign has affected thousands of companies from 2024 to 2026, with activity potentially linked to 4,532 unique organization email domains. The United States accounted for 63.7% of total victims, while activity was also observed in India, Singapore, the United Kingdom, Canada, Saudi Arabia, South Africa, and other countries. Technology, manufacturing, and education were among the most targeted industries. ANY.RUN research found 48% of targeted email addresses were potentially compromised.

Attack Method

Mirage2FA is a commercial phishing-as-a-service toolkit that targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication. By stealing passwords and session cookies, attackers gain access to authenticated Microsoft 365 sessions and SSO-connected services. ANY.RUN's research uncovered more than 9,000 potential compromise events involving cookie and password theft, SSO logins, and 2FA bypass. Once an authenticated Microsoft 365 session is hijacked, a path for impersonation, fraud, and further compromise is created.

Risk Reduction

Organizations can reduce exposure by strengthening authentication, detecting campaign behavior, and treating session theft as an identity incident. ANY.RUN's Interactive Sandbox exposes redirects, scripts, WebSocket activity, and fake Microsoft 365 login pages to help SOC teams identify phishing behavior before account compromise. Moving beyond traditional MFA to phishing-resistant authentication and stronger session controls is recommended.

1 source

Mirage2FA phishing campaign hits 4,500 companies, bypasses Microsoft 365 2FA