Bottom line: A sophisticated phishing campaign, Mirage2FA, has compromised Microsoft 365 accounts of over 4,500 US and EU companies.
What's happening: Researchers from ANY.RUN analyzed the campaign, which began in 2024 and targeted 4,500 companies in the US and EU, using 48% of targeted email addresses. The attackers used commercial phishing-as-a-service toolkit, exploiting legitimate login flows and bypassing two-factor authentication.
What to do: Security teams should immediately review their Microsoft 365 account security settings to ensure that two-factor authentication is enabled and set to a minimum CVSS score of 4.5 to prevent further exploitation.