A large phishing campaign called Mirage2FA is targeting Microsoft 365 users by stealing credentials and authenticated sessions, exposing thousands of organizations.
A new phishing campaign targeting Microsoft 365 users is highlighting a growing problem in enterprise cybersecurity: multi-factor authentication is no longer enough when attackers can steal an already authenticated session.
The campaign, known as Mirage2FA, has been linked to activity involving thousands of organizations in the United States and Europe. Research from cybersecurity company ANY.RUN, reported Tuesday by The Hacker News, identified activity associated with 4,532 unique organization email domains. More than 9,000 potential compromise events involving stolen passwords, session cookies, single sign-on activity and two-factor authentication bypass were identified during the research.
The numbers do not mean that all 4,532 organizations were definitively breached.
That distinction matters.
The research identifies organizations and potential compromise events associated with the campaign, but it does not establish that every targeted company suffered a confirmed security incident.
What the campaign does demonstrate, however, is how attackers are changing their strategy.
Instead of simply trying to steal a password, they are increasingly trying to steal the authenticated session that comes after the user has already logged in.
The Weakness Behind Modern Phishing

Traditional phishing is relatively straightforward.
An attacker sends a convincing message containing a link to a fake login page. The victim enters a username and password, and the attacker captures the credentials.
Multi-factor authentication was designed to make that approach less effective.
Even if an attacker knows the password, they still need another authentication factor.
That forced criminals to adapt.
Mirage2FA is an example of that adaptation.
The campaign uses an Adversary-in-the-Middle, or AiTM, approach to place the attacker between the victim and the legitimate Microsoft authentication process.
The victim may still see a real-looking Microsoft login experience and complete the normal authentication steps.
The problem is that the attacker can intercept information exchanged during the process, including credentials and authentication session data.
The result can be more dangerous than simply stealing a password.
An attacker may obtain a session that has already passed authentication.
Why Session Theft Is So Important
A session token essentially tells a service that a user has already authenticated.
Instead of asking the user to enter their password every time they open Outlook, Teams or another connected service, the system can rely on authentication tokens to maintain that session.
This is essential for modern cloud computing.
It is also a valuable target.
Microsoft’s own documentation warns that stolen tokens can potentially be replayed by attackers to access resources as the legitimate user. Microsoft recommends phishing-resistant credentials, device and risk-based Conditional Access and other measures to reduce the risk of token theft and replay.
That creates a difficult security problem.
The company may have successfully deployed MFA.
The employee may have correctly completed the MFA challenge.
And yet the account can still become compromised if the attacker steals the authenticated session afterward.
This is why security teams are increasingly treating identity and session security as separate problems from password security.
Microsoft 365 Is a High-Value Target
Microsoft 365 accounts are particularly attractive because one compromised identity can provide access to multiple business services.
An employee account may be connected to email, cloud storage, collaboration tools and other enterprise applications through single sign-on.
If an attacker gains control of that identity, the potential impact extends beyond one inbox.
A compromised account can become a starting point for further attacks inside an organization.
The Mirage2FA research found that technology, manufacturing and education were among the industries targeted, while the United States represented the largest share of the organizations identified in the research. Activity was also observed in countries including the United Kingdom, Canada, India, Singapore and Saudi Arabia.
That geographic spread is significant.
This is not a campaign aimed at one specific industry or one specific country.
It demonstrates how phishing-as-a-service can be scaled across thousands of potential targets.
The Rise of Phishing-as-a-Service
One reason campaigns like Mirage2FA are concerning is the increasing availability of phishing-as-a-service tools.
Attackers do not necessarily need to build every component of an operation themselves.
Specialized criminal services can provide phishing infrastructure, fake authentication pages and mechanisms designed to capture credentials or sessions.
That lowers the technical barrier for criminals.
The result is a cybersecurity environment where sophisticated techniques can be deployed at a much larger scale.
The attacker does not need to compromise Microsoft’s infrastructure directly.
They only need to convince a user to interact with a carefully designed malicious workflow.
MFA Still Matters
It would be a mistake to interpret Mirage2FA as proof that MFA is useless.
It is not.
Multi-factor authentication remains one of the most important protections available to users and organizations.
The problem is that not all MFA is equally resistant to phishing.
Traditional methods involving codes, push notifications or authentication prompts can sometimes be manipulated through social engineering or intercepted through adversary-in-the-middle techniques.
Security teams are therefore increasingly encouraged to adopt phishing-resistant authentication, including passkeys and hardware-backed authentication methods.
Microsoft itself recommends phishing-resistant credentials as part of a broader defense against token theft and identity compromise.
The lesson is not to abandon MFA.
It is to move toward stronger forms of it.
Why Password Resets May Not Be Enough
Another important lesson from session theft is that changing a password does not necessarily end an attack.
If an attacker has already obtained an authenticated session token, simply changing the password may not immediately invalidate every compromised session.
Security teams need to identify compromised identities, revoke sessions and tokens where appropriate, investigate connected applications and determine how the attacker obtained access.
That makes incident response more complicated.
The security team is no longer asking only:
“Was the password stolen?”
It also needs to ask:
“Which sessions were compromised, what resources did they access and where did those sessions originate?”
That is a much broader investigation.
The Cloud Changes the Security Perimeter
The Mirage2FA campaign illustrates a fundamental change in enterprise security.
Years ago, companies could think of their network as the main security boundary.
Today, employees work from laptops, smartphones and home networks while accessing cloud applications from almost anywhere.
Identity has become the new perimeter.
If an attacker controls a trusted identity, traditional network defenses may not be enough.
That is why cloud security increasingly depends on continuous verification.
Organizations need to evaluate not just whether a user authenticated successfully, but also whether the behavior afterward makes sense.
An unusual location, device, session or access pattern can provide clues that an otherwise valid login is being abused.
What Businesses Should Do
The first step is to strengthen authentication.
Organizations should consider phishing-resistant MFA, including passkeys or security keys, especially for administrators and other high-value accounts.
They should also monitor unusual authentication behavior and have procedures for quickly revoking compromised sessions.
Employees remain an important part of the defense.
Unexpected Microsoft 365 login requests, unusual authentication prompts and suspicious links should be treated carefully.
Security awareness training is useful, but companies should not depend entirely on employees identifying sophisticated phishing attacks.
The technical controls need to assume that some malicious messages will eventually reach users.
The Bigger Picture
Mirage2FA is part of a broader evolution in cybercrime.
Attackers are moving away from the idea that stealing a password is the ultimate objective.
Increasingly, the goal is to steal trust.
If an attacker can obtain a valid authenticated session, they may not need to break the authentication system at all.
They can attempt to operate inside it.
That makes identity security one of the most important areas of enterprise cybersecurity.
And as organizations continue moving workloads into the cloud, that importance will only grow.
The Mirage2FA campaign is a warning that modern authentication systems are facing a new generation of attacks.
The research does not prove that every organization connected to the campaign was breached, but the scale of the activity is significant: thousands of organizational domains and thousands of potential compromise events have been identified.
The most important lesson is simple:
MFA can protect an account from stolen passwords, but it cannot by itself solve every identity-security problem.
Attackers are now targeting the authenticated sessions that come after login.
For businesses, that means the future of cloud security will depend increasingly on phishing-resistant authentication, continuous monitoring, session protection and rapid response to identity compromise.
The password may have been the key to the cloud.
Now, increasingly, the session is the key attackers want to steal.