Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

A massive wave of attacks, dubbed “Mirage2FA,” has struck over 4,500 companies in the US and EU, compromising sensitive login credentials and leaving a trail of exposed identities in its wake. The campaign’s operators have leveraged a clever manipulation of Microsoft 365 login flows to bypass multi-factor authentication (MFA) protections, allowing them to gain unauthorized access to high-value targets.

The attacks rely on a sophisticated understanding of the Microsoft 365 ecosystem, exploiting a combination of vulnerabilities and misconfigured settings within the platform. Specifically, attackers are targeting organizations that have enabled the “passwordless” login feature in Microsoft 365, which relies on a user’s Azure Active Directory (AAD) credentials to authenticate users without requiring a traditional password.

When a user attempts to log in using this feature, their AAD session is established through an authentication flow that appears to be legitimate. However, the attackers have found a way to manipulate this process, inserting themselves into the authentication chain and hijacking the login session. This allows them to bypass MFA protections and gain access to sensitive resources within the targeted organization.

The Mirage2FA campaign’s focus on Microsoft 365 is telling – the platform’s widespread adoption across businesses of all sizes has created a vast attack surface for threat actors to exploit. While passwordless authentication offers numerous benefits, including enhanced security through the removal of passwords, it also introduces new vulnerabilities if not properly configured or monitored.

As more organizations transition to cloud-based services and adopt advanced authentication methods like passwordless login, they must be aware of the evolving threat landscape and take proactive steps to mitigate the risks. This includes regular security audits, thorough configuration reviews, and vigilant monitoring of user behavior within Microsoft 365.

For readers looking to protect their own organizations from similar attacks, a crucial takeaway is to carefully evaluate the security implications of adopting emerging authentication technologies like passwordless login. While these solutions offer promise in terms of convenience and enhanced security, they must be implemented with caution and monitored closely for signs of suspicious activity.

Regularly reviewing Microsoft 365 configuration settings, staying up-to-date on the latest threat intelligence, and maintaining robust incident response plans will help organizations stay ahead of sophisticated threats like Mirage2FA. By prioritizing proactive security measures and fostering a culture of awareness within their teams, businesses can better defend against these types of attacks and safeguard their sensitive data and assets.


Source: The Hacker News — 2026-08-25