Over 4,500 Organizations Targeted in Mirage2FA Campaign Abusing Microsoft 365 Login Flow
Between 2024 and 2026, the Mirage2FA phishing campaign targeted over 4,500 organizations worldwide. Leveraging sophisticated Adversary-in-the-Middle (AiTM) proxies, the toolkit bypasses legacy two-factor authentication to swipe both passwords and active session cookies. With nearly 50% of targeted inboxes potentially compromised, the campaign proves that basic password resets won't cut it, forcing organizations to adopt phishing-resistant FIDO2/passkey authentication and aggressive session revocation.