A large-scale phishing campaign known as Mirage2FA has reportedly targeted more than 4,500 organizations, demonstrating how cybercriminals can compromise Microsoft 365 accounts even when two-factor authentication (2FA) is enabled.
Operating as a phishing-as-a-service platform, Mirage2FA has been active from 2024 to 2026. Research indicates that 48% of targeted email addresses were potentially compromised, with the United States accounting for 63.7% of identified victims. India, Singapore, the UK, Canada, Saudi Arabia and South Africa were also targeted.
The attack relies on an Adversary-in-the-Middle (AiTM) technique. Rather than simply stealing passwords, attackers intercept legitimate authentication flows and capture session cookies after users authenticate. These cookies can enable criminals to hijack authenticated Microsoft 365 sessions without directly defeating the second authentication factor.
Researchers identified more than 9,000 potential compromise events involving password theft, cookie capture, SSO authentication and 2FA bypass. Around 4,532 unique organizational email domains were potentially associated with the activity, with technology, manufacturing and education among the targeted sectors.
The greater danger emerges after the initial compromise. A hijacked Microsoft 365 identity can potentially provide access to corporate email and connected applications. Through Single Sign-On (SSO), one compromised session can expand the attack surface across multiple enterprise services, creating opportunities for impersonation, business email compromise, data theft and further intrusion.
Authentication Must Become Continuous:
Mirage2FA exposes an important weakness in enterprise identity security: successful 2FA does not necessarily mean the session remains trustworthy. Organizations increasingly need to protect the entire authentication lifecycle, not simply the login event.
Security strategies should therefore combine phishing-resistant authentication with continuous session monitoring, behavioral analytics, device intelligence, conditional access and rapid token revocation. As attackers shift from stealing credentials to stealing authenticated sessions, enterprises must similarly evolve from “verify once” toward “verify continuously.”
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




