Between 2024 and 2026, the Mirage2FA phishing-as-a-service campaign has significantly impacted thousands of companies by exploiting Microsoft 365 login flows. This sophisticated toolkit has been able to bypass two-factor authentication, leading to the compromise of many corporate accounts. A study by ANY.RUN reveals that approximately 48% of targeted email addresses were potentially compromised, with a majority of these companies being based in the United States. Attackers have been stealing passwords and session cookies, gaining access to authenticated Microsoft 365 sessions and other services connected through single sign-on. This not only exposes sensitive data but also increases identity-related risks for organizations.

The campaign has a wide reach, affecting companies across the United States, India, Singapore, the United Kingdom, and several other countries. Mirage2FA activity has been detected in over 4,500 unique organization email domains, particularly targeting industries like technology, manufacturing, and education. The research highlights that session theft is a major risk, with over 9,000 potential compromise events linked to cookie and password theft, SSO logins, and 2FA bypass.

The impact of these attacks extends beyond initial account compromise, affecting SSO-connected apps and internal workflows, thus broadening the attack radius and increasing containment costs. It is crucial for companies to enhance their authentication processes, detect campaign behaviors, and treat session theft as identity incidents. By integrating sandboxing into workflows, security operations centers can investigate suspicious content and identify phishing activities earlier, reducing the overall impact.

Organizations are encouraged to focus on phishing-resistant authentication and to implement response procedures designed for session theft. Early detection and the use of threat intelligence feeds are essential for identifying and mitigating threats like Mirage2FA, which showcase the evolution of phishing beyond mere credential theft.