What happened
Researchers have detailed the scale of Mirage2FA, a commercial phishing-as-a-service kit running since 2024 that has targeted more than 9,400 unique Microsoft 365 email addresses across roughly 4,500 organizations, mostly in the US, with the UK, Canada, India, Singapore, Saudi Arabia, and South Africa also affected. An estimated 48% of targets — over 4,500 accounts — were potentially compromised, with technology, manufacturing, and education the most-targeted sectors. Rather than attacking MFA directly, the kit runs an adversary-in-the-middle proxy that sits between the victim and the real Microsoft 365 login page, capturing the session cookie once the user completes a legitimate login and MFA challenge.
Why it matters for your business
A password reset does nothing against this technique, because the attacker isn't stealing the password — they're stealing the already-authenticated session. Any company relying on standard MFA prompts for Microsoft 365 without phishing-resistant authentication, like hardware security keys, is exposed to the same technique. Once a session is hijacked, the attacker inherits access to email, SharePoint, and any SSO-connected app the victim was signed into.
What to watch next
Security researchers are recommending organizations treat any suspected session theft as an identity incident requiring session revocation, not just a password reset, and move toward phishing-resistant authentication where the account's sensitivity justifies it.
