Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows
Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication. According to ANY.RUN research, 48% of targeted email addresses were potentially compromised. Most of the affected companies are US-based. Mirage2FA Campaign
Contenu original affiche; la traduction localisee n'est pas encore disponible.
Ce qui s'est passé
Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication. According to ANY.RUN research, 48% of targeted email addresses were potentially compromised. Most of the affected companies are US-based. Mirage2FA Campaign
Pourquoi c'est important
The incident may affect operational continuity, asset safety or trust around Microsoft. Watch for verified scope and remediation.
Entités concernées
Voir les preuves
2 articles · 1 publication d'origine · 1 independantes
- The Hacker NewsSource primaire · Confirme · EN · 100%Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows ↗
- The Hacker NewsSource primaire · Confirme · EN · 49%NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions ↗
Affirmations
- Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows Observé
Divergences
Aucune divergence importante détectée dans les preuves disponibles.
Chronologie
- Premier signalement
Mouvement de marché suivant l'événement
La réaction du marché n'est pas encore disponible pour cet actif et cette fenêtre.