Between 2024 and 2026, a spate of phishing attacks under the name “Mirage2FA” has targeted over 4,500 companies across the US and EU regions. The campaign exploits Microsoft 365 login flows, enabling attackers to bypass two-factor authentication (2FA) protection and hijack authenticated sessions.
How Mirage2FA Works
The attack begins with compromised credentials or stolen session cookies. Once those are obtained, attackers can access authenticated Microsoft 365 sessions as if they were legitimate users. That access often extends to services connected via single sign-on (SSO), including trusted apps and internal tools. In practice, gaining control of an active session lets attackers act on behalf of employees—sending emails, accessing sensitive data, and committing fraud.
Scope, Industries, and Geographic Reach
Research indicates that about 4,532 unique organization email domains have been hit so far. Roughly 63.7% of the affected companies are based in the United States. Other impacted regions include India, Singapore, the UK, Canada, Saudi Arabia, and South Africa. The most frequently targeted sectors are technology, manufacturing, and education.
The damage goes deeper than lost passwords. There are well over 9,000 identified incidents involving stolen cookies, passwords, or SSO logins—all components of what’s known as session theft. In nearly half of targeted email accounts (about 48%), compromise is now considered probable.
Why 2FA Isn’t Enough—And What Firms Should Do
Despite having two-factor authentication enabled, organizations remain vulnerable if attackers can hijack sessions. With session tokens in hand, intruders can bypass both the login process and 2FA validation. This puts any connected apps, internal workflows, and trusted corporate assets at risk.
To counter Mirage2FA, companies should adopt stronger identity safeguards: phishing-resistant authentication methods, more stringent session management, and behavioral analytics to flag anomalous activity. Real-time threat intelligence feeds that track evolving attack infrastructure—malicious URLs, domains, IPs—also play a key role in detection and response.
Treating session theft itself as a major identity breach is essential. When a session is compromised, it’s not sufficient to simply reset a password. Companies need to revoke tokens, analyze linked accounts or services, and further investigate the impacted identity across systems.
Mirage2FA underscores how phishing continues to evolve—no longer just stealing credentials, but taking over authenticated sessions to evade defenses like MFA. With thousands of organizations already affected—especially in the US—security leaders must rethink what protection looks like in a world where access can be seized without ever bypassing 2FA via traditional means.