Return to Threats

Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows

thehackernews.com 2026-08-25 malicious AI use High

What Happened

Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication. According to ANY.RUN research, 48% of targeted email addresses were potentially compromised. Most of the affected companies are US-based. Mirage2FA Campaign

Why It Matters

The report describes the Mirage2FA phishing-as-a-service campaign, which targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication, with thousands of companies affected from 2024 to 2026. The article says 4,500 US and EU companies were hit and that ANY.RUN research found 48% of targeted email addresses were potentially compromised. RealGround analysis: this is best classified as malicious AI use only if the campaign is leveraging AI-enabled phishing automation or social engineering at scale; otherwise it is primarily a broader identity and email security threat with implications for account takeover, credential theft, and phishing resilience.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to malicious AI use. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/08/mirage2fa-surge-hits-4500-us-and-eu.html

Talk to AI CISO