Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

0
High
Phishingphishing
Published: 09/07/2026 (09/07/2026, 15:39:51 UTC)
Source: Bleeping Computer

Description

BigBear 2.0 is a phishing-as-a-service framework that has been used to bypass multi-factor authentication (MFA) at 258 organizations, stealing over 5,000 Microsoft 365 credentials. It operates as an adversary-in-the-middle proxy, intercepting passwords, MFA tokens, and session cookies to hijack authenticated sessions. The campaign targets Microsoft 365 users globally, leveraging geo-matched residential proxies to evade detection and custom JavaScript to disable stronger FIDO2/WebAuthn authentication methods. The phishing infrastructure remains partially active, with multiple affiliate operators receiving stolen credentials in real time. Organizations affected should reset passwords, revoke sessions, and enforce phishing-resistant authentication methods.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/07/2026, 16:07:25 UTC

Technical Analysis

BigBear 2.0 is a phishing-as-a-service (PhaaS) framework that uses an Evilginx2-based adversary-in-the-middle proxy to intercept Microsoft 365 credentials, including passwords, multi-factor authentication tokens, and session cookies, enabling attackers to bypass MFA and hijack user sessions. The service manages multiple VPS nodes and uses geo-matched residential proxies to avoid triggering Microsoft's security alerts. It also employs custom JavaScript to disable FIDO2/WebAuthn browser functionality, forcing victims to use weaker authentication methods. CloudSEK researchers accessed the control panel and found that the campaign compromised 258 distinct organizations, exfiltrating over 5,000 credential records and affecting over 3,300 unique victim IPs across 40+ countries. The phishing infrastructure has been offline for nearly three weeks, but the administration panel remains accessible. The service is leased to multiple affiliate operators who receive stolen credentials in real time via Telegram bots. CloudSEK has notified law enforcement and affected organizations.

Potential Impact

The campaign successfully bypassed MFA protections at 258 organizations, resulting in the theft of over 5,000 Microsoft 365 credentials, including plaintext passwords, MFA tokens, and session cookies. This allows attackers to hijack authenticated sessions and gain unauthorized access to Microsoft 365 services such as Exchange Online, Teams, SharePoint, OneDrive, and Entra ID. Compromise of these accounts can lead to exposure of sensitive emails and files, and potentially broader access through single sign-on integrations. The use of geo-matched proxies and disabling of phishing-resistant authentication methods increases the likelihood of successful account takeover without triggering security alerts.

Defensive Guidance

Organizations potentially affected by BigBear should immediately reset exposed passwords, revoke all active sessions, refresh authentication tokens, and enforce re-authentication for high-privileged accounts. It is recommended to enforce phishing-resistant authentication methods such as FIDO2/WebAuthn and implement Conditional Access policies requiring managed devices rather than relying on geo-location signals. CloudSEK has notified law enforcement and affected entities. The phishing infrastructure has been offline for nearly three weeks, but the administration panel remains online, so vigilance is advised.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.8,"severitySource":"default","classifier":"rss-v2"}

Threat ID: 6a9ee135acd9273b49e62b98

Added to database: 09/07/2026, 16:07:17 UTC

Last enriched: 09/07/2026, 16:07:25 UTC

Last updated: 09/08/2026, 03:14:34 UTC

Views: 19

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses