Home / Aug 26, 2026 / Story
0
#4 The Hacker News general August 25, 2026 at 11:56 UTC

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

By [email protected] (The Hacker News)

AI Summary

The Mirage2FA phishing-as-a-service toolkit has targeted 4,500 US and EU companies between 2024 and 2026, abusing legitimate Microsoft 365 login flows to bypass two-factor authentication, with ANY.RUN research indicating 48% of targeted email addresses were potentially compromised. The campaign's multi-year persistence and scale make it a significant threat to enterprise Microsoft 365 deployments.

Relevance score: 82.0/100

# More from August 26