August 31, 2026
Phishing Kits Are Beating MFA, and Orlando Isn't Exempt
New research on the Mirage2FA phishing kit shows attackers stealing Microsoft 365 sessions after MFA passes. What Orlando businesses should do now.
Chris Archer Sales & Marketing Director
Reviewed by Reade Taylor, Founder & President The attacker logs in right behind you
For years the standard advice to every Orlando business has been the same. Turn on multi-factor authentication and most phishing stops working. That advice is now out of date, and fresh research published this week shows exactly how far out of date it is.
On August 25, researchers at ANY.RUN published an analysis of a phishing kit called Mirage2FA. It does not try to crack MFA. It waits for the victim to complete it. The kit sits between the victim and the real Microsoft 365 login page as a live proxy. You type your password on what looks like the Microsoft sign-in screen, approve the MFA prompt on your phone, and the kit quietly relays all of it to Microsoft in real time. Microsoft issues a valid session, and the attacker keeps the session cookie. From that moment they are inside your account, MFA satisfied, no alarms tripped.
Security folks call this an adversary-in-the-middle attack. The part worth sitting with is the scale. This is not a proof of concept. It is a subscription product that criminals rent.
What the numbers say
The ANY.RUN team tracked Mirage2FA activity from September 2024 through July 2026 and tied it to 3,518 organizations. Of 9,426 email addresses that received the phishing lures, 4,532 accounts were potentially compromised. That is roughly half, an astonishing hit rate for email-based attacks.
The United States took most of the damage. American victims made up 2,885 of the total, about 64 percent, across a campaign that touched 94 countries. The Hacker News reports the campaign has been surging this August.
Two more details matter for anyone running a business here in Central Florida. First, the lures arrive as ordinary-looking email attachments, mostly .htm files along with .xhtml and .svg files, over a thousand distinct samples so far. Nobody thinks twice about an attachment that opens in a browser. Second, of the 9,332 compromise events researchers recorded, 4,561 involved theft of an authenticated session cookie. In other words, in about half the cases the attacker did not just get a password. They got a logged-in Microsoft 365 session, which often unlocks every other app connected to it through single sign-on.
The most targeted sectors were technology at 19.2 percent, manufacturing at 11.1 percent, education at 9.9 percent, and consulting at 8.3 percent. If you run a manufacturing or industrial shop, you are squarely in the demographic.
Stuck on something like this right now?
Talk it through with a real US-based engineer, 24/7, no phone trees: (407) 587-0089.
Book a Free Strategy SessionWhy this lands on Orlando businesses
Nearly every small business we see in Orlando, Winter Springs, Tampa Bay, and Jacksonville runs on Microsoft 365. Email, files, Teams, accounting integrations, all behind one login. Most of them turned on MFA sometime in the last few years, got the compliance checkbox, and moved on. The assumption baked into that checkbox is that MFA ends the conversation.
Mirage2FA is built to have the conversation anyway. And because the kit is rented out as a service, the attacker does not need any technical skill. They need a mailing list and a monthly subscription.
A stolen session at a 20-person law office or property management firm plays out the same way every time. The attacker reads the mailbox for a week, learns who pays the invoices, then sends a wire change request from the real account at the moment it will look most routine. No malware, no ransomware note, just money gone.
Your IT provider might be the way in
Here is the detail from this research that deserves more attention than it is getting. CyberSecurityNews notes that MSSPs, the security providers themselves, feature among the most affected sectors. One compromised provider account can expose every customer that provider manages.
That is worth an uncomfortable question or two for whoever runs your IT. When did they last review your Microsoft 365 conditional access policies? Do they enforce phishing-resistant sign-in on their own admin accounts, the ones with the keys to your tenant? If the answers are vague, or if your tickets have been sitting in a queue somewhere, that is a signal worth acting on. We wrote up what a clean, low-drama transition looks like on our switching IT providers page, including how co-managed arrangements let you add coverage without firing anyone.
Five changes worth making this week
None of this requires a big project. It requires attention.
- Block or sandbox .htm, .xhtml, and .svg attachments at the mail gateway. Almost no legitimate business process depends on them.
- Shorten session lifetimes and require reauthentication for sensitive apps, so a stolen cookie expires before it becomes a payday.
- Move your highest-risk users, the owner, the bookkeeper, anyone in finance, to phishing-resistant methods like FIDO2 security keys or passkeys. A hardware-bound credential cannot be relayed through a proxy page.
- Set conditional access to flag impossible travel and unfamiliar devices, and make sure a human actually reviews those alerts.
- Write down the response runbook before you need it. Resetting a password does not end one of these incidents. You have to revoke active sessions and tokens too.
Our cybersecurity team runs this kind of Microsoft 365 hardening as a standard engagement, and our SOC watches for the session anomalies these kits leave behind. The tooling is designed to catch what the MFA checkbox misses. If you already have internal IT, a co-managed setup can layer the monitoring on top of what your team handles day to day.
MFA is still worth having. It stops the lazy attacks cold. But the criminals selling Mirage2FA subscriptions have moved on to the next step, and Orlando businesses that treat MFA as the finish line are exactly who those subscriptions are aimed at.
If you want a second set of eyes on your Microsoft 365 tenant, reach out or call us at (407) 587-0089. We are based in Winter Springs, we answer the phone with real humans around the clock, and we serve businesses across Orlando, Tampa Bay, and Jacksonville.
#CyberSecurity #ManagedIT #Microsoft365 #Phishing #Orlando
This article is for general informational purposes only and is not legal, compliance, insurance, or other professional advice. Threats, technologies, and regulations change quickly; confirm current requirements with your own advisors before acting. See our full disclaimer.