Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

A sprawling cyberattack campaign, dubbed “Mirage2FA,” has compromised the login credentials of over 4,500 companies across the United States and Europe. The attackers have been exploiting vulnerabilities in Microsoft 365’s authentication flows to gain unauthorized access to corporate networks, raising concerns about the security posture of these organizations.

At its core, Mirage2FA involves a sophisticated phishing campaign that manipulates the two-factor authentication (2FA) mechanism built into Microsoft 365. By sending carefully crafted emails, attackers trick users into divulging their login credentials and 2FA codes, which are then used to bypass conventional security measures. The exploit leverages a previously unknown weakness in the way Microsoft 365 handles authentication sessions, allowing malicious actors to gain seamless access to company resources without triggering standard security alerts.

The scope of the breach is staggering, with affected companies spanning various industries, including finance, healthcare, and technology. Notably, several high-profile organizations have been impacted, underscoring the potential for catastrophic consequences should attackers exploit their compromised credentials. According to sources close to the investigation, the hackers appear to be using the breached login information to map out corporate networks, identifying key choke points where they can exert maximum control.

One of the most disturbing aspects of Mirage2FA is its ability to traverse organizational boundaries, thanks to a technique called cross-domain privilege escalation (CDPE). By compromising one employee’s account, attackers can pivot into other parts of the network, granting them access to sensitive data and resources. The hackers have demonstrated an uncanny understanding of Microsoft 365’s architecture, tailoring their exploits to evade traditional security controls.

The Mirage2FA campaign serves as a stark reminder of the evolving threat landscape, where sophisticated attacks often rely on subtle vulnerabilities rather than brute force tactics. As companies continue to invest in robust security measures, attackers are adapting, using social engineering and clever exploitation techniques to outmaneuver defenders. In light of this incident, organizations would do well to review their Microsoft 365 configurations, ensuring that all authentication flows are properly secured and monitoring for suspicious login activity.

The Mirage2FA saga highlights the critical importance of robust password management practices, regular security audits, and employee education on phishing tactics. By prioritizing these measures, companies can reduce their vulnerability to such attacks and minimize the risk of compromised credentials being used as a springboard for more extensive breaches.


Source: The Hacker News — 2026-08-25