A widespread phishing campaign leveraging the Mirage2FA phishing-as-a-service (PhaaS) toolkit has impacted roughly 4,500 organizations across the United States and the European Union, according to research published by ANY.RUN on August 25, 2026. The campaign, active from 2024 through 2026, specifically targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication (2FA).
ANY.RUN's analysis indicates that 48% of the email addresses targeted in the campaign were potentially compromised, leading to unauthorized access to Microsoft 365 accounts and potential data breaches. The majority of affected companies are based in the US, with a significant number also in the EU.
The Mirage2FA toolkit employs adversary-in-the-middle (AiTM) techniques to intercept session cookies and authentication tokens, allowing attackers to bypass 2FA protections. By presenting users with a realistic Microsoft 365 login page, the toolkit captures credentials and session data in real time, granting attackers persistent access to compromised accounts.
No specific CVE or zero-day vulnerability has been associated with this campaign. Instead, the attack relies on social engineering and the abuse of standard authentication flows, making it particularly difficult for organizations to detect using traditional security measures.
The findings underscore the growing threat of PhaaS platforms, which lower the barrier to entry for cybercriminals and enable large-scale campaigns with minimal technical expertise. The success of Mirage2FA highlights the limitations of legacy 2FA methods, such as SMS or one-time passwords, which are vulnerable to AiTM attacks.
Organizations are advised to enforce phishing-resistant MFA, such as FIDO2/WebAuthn, implement conditional access policies, and conduct regular user awareness training to recognize phishing attempts. Additionally, monitoring for anomalous login activity and session anomalies can help detect AiTM attacks early.
While the exact number of compromised accounts remains unverified, the scale of the campaign and the high success rate reported by ANY.RUN emphasize the urgent need for enhanced security measures in enterprise environments.