By The Hacker News
Publication Date: 2026-08-25 11:56:00
Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication.
According to ANY.RUN research, 48% of targeted email addresses were potentially compromised. Most of the affected companies are US-based.
Mirage2FA Campaign Scope and Impact
By stealing passwords and session cookies, attackers can gain access to authenticated Microsoft 365 sessions and SSO-connected services. This creates significant identity-related risks for companies, potentially exposing corporate email, trusted business accounts, and other sensitive data.
Once an authenticated Microsoft 365 session is hijacked, a path for impersonation, fraud, and further compromise is created.
![]() |
| Key takeaways about Mirage2FA by ANY.RUN |
The campaign has a broad geographic and corporate reach….



