CyberSecurity News
Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows
AI summary
A phishing campaign known as Mirage2FA has impacted approximately 4,500 companies in the US and EU. The campaign, which has been active from 2024 to 2026, targets Microsoft 365 accounts by exploiting legitimate login flows and evading two-factor authentication. Research by ANY.RUN found that nearly half of the targeted email addresses may have been compromised. The majority of affected companies are based in the US, with some also located in the EU. The Mirage2FA campaign utilizes a commercial phishing-as-a-service toolkit to carry out its attacks.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

