< BACK TO NEWS
negativeSYS.SOURCE: The Hacker News2026-08-25T17:26:15+05:30

Mirage2FA Phishing Campaign Exploits Microsoft 365 Login Flows to Compromise 4,500 Organizations

The Mirage2FA phishing campaign exploited Microsoft 365 login flows to compromise 4,500 organizations by bypassing two-factor authentication through session hijacking and credential theft. The attack highlights critical identity security risks and emphasizes the need for phishing-resistant authentication and behavioral detection measures.

Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication.

According to ANY.RUN research, 48% of targeted email addresses were potentially compromised. Most of the affected companies are US-based.

Mirage2FA Campaign

Read original article

*** END OF TRANSMISSION ***