Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows
- ID
- 17594
- Status
- summarized
- Published
- 25 Aug 2026, 7:56 PM
- Fetched
- 25 Aug 2026, 8:36 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/08/mirage2fa-surge-hits-4500-us-and-eu.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 7.5
- Created
- 25 Aug 2026, 8:38 PM
- Tags
- Audience
- developerssaas_foundersai_agent_users
What happened
Mirage2FA, a commercial phishing-as-a-service toolkit, has targeted 4,532 organizations globally since 2024 by bypassing Microsoft 365 2FA via session cookie and password theft. ANY.RUN reports that 48% of targeted emails were potentially compromised, with victims concentrated in the US but also spanning Singapore, India, and the UK, heavily impacting the technology and manufacturing sectors.
Why it matters
If your company relies on Microsoft 365 and SSO, standard 2FA is insufficient against this AiTM attack; you must implement conditional access policies that revoke or restrict session tokens based on anomalies to prevent attackers from pivoting into connected SaaS apps.
Discussion angle
Practical steps for configuring Microsoft 365 tenant policies to detect and invalidate stolen session cookies, rather than relying solely on MFA enforcement.