Threat Intelligence

Phishing Kit 'Mirage2FA' Bypasses Two-Factor Authentication, Hits 4,500 Companies

The Hacker News · 25 Aug 2026
Key Takeaway Train staff to recognise phishing attempts and consider phishing-resistant authentication methods, since traditional two-factor authentication can still be bypassed by advanced attack kits.

A large-scale phishing campaign known as Mirage2FA has affected around 4,500 companies across the United States and Europe between 2024 and 2026, according to research from ANY.RUN. The campaign uses a commercial phishing-as-a-service kit that specifically targets Microsoft 365 accounts, and most affected organisations are based in the US.

What makes Mirage2FA particularly dangerous is its ability to abuse legitimate Microsoft 365 login flows to bypass two-factor authentication (2FA), a security measure many businesses rely on as a strong defence against account takeovers. ANY.RUN's research found that 48% of targeted email addresses were potentially compromised, suggesting the toolkit is highly effective despite 2FA protections being in place.

For small and medium businesses using Microsoft 365 for email and collaboration, this campaign is a reminder that two-factor authentication alone is not foolproof against sophisticated phishing techniques. Attackers using kits like Mirage2FA can intercept authentication sessions in real time, making user awareness and additional monitoring critical layers of defence alongside standard security tools.

phishing Microsoft 365 two-factor authentication Mirage2FA account security

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.