BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
BigBear 2.0 is a phishing-as-a-service framework that has been used to bypass multi-factor authentication (MFA) at 258 organizations, stealing over 5,000 Microsoft 365 credentials. It operates as an adversary-in-the-middle proxy, intercepting passwords, MFA tokens, and session cookies to hijack authenticated sessions. The campaign targets Microsoft 365 users globally, leveraging geo-matched residential proxies to evade detection and custom JavaScript to disable stronger FIDO2/WebAuthn authentication methods. The phishing infrastructure remains partially active, with multiple affiliate operators receiving stolen credentials in real time. Organizations affected should reset passwords, revoke sessions, and enforce phishing-resistant authentication methods.
AI Analysis
Technical Summary
BigBear 2.0 is a phishing-as-a-service (PhaaS) framework that uses an Evilginx2-based adversary-in-the-middle proxy to intercept Microsoft 365 credentials, including passwords, multi-factor authentication tokens, and session cookies, enabling attackers to bypass MFA and hijack user sessions. The service manages multiple VPS nodes and uses geo-matched residential proxies to avoid triggering Microsoft's security alerts. It also employs custom JavaScript to disable FIDO2/WebAuthn browser functionality, forcing victims to use weaker authentication methods. CloudSEK researchers accessed the control panel and found that the campaign compromised 258 distinct organizations, exfiltrating over 5,000 credential records and affecting over 3,300 unique victim IPs across 40+ countries. The phishing infrastructure has been offline for nearly three weeks, but the administration panel remains accessible. The service is leased to multiple affiliate operators who receive stolen credentials in real time via Telegram bots. CloudSEK has notified law enforcement and affected organizations.
Potential Impact
The campaign successfully bypassed MFA protections at 258 organizations, resulting in the theft of over 5,000 Microsoft 365 credentials, including plaintext passwords, MFA tokens, and session cookies. This allows attackers to hijack authenticated sessions and gain unauthorized access to Microsoft 365 services such as Exchange Online, Teams, SharePoint, OneDrive, and Entra ID. Compromise of these accounts can lead to exposure of sensitive emails and files, and potentially broader access through single sign-on integrations. The use of geo-matched proxies and disabling of phishing-resistant authentication methods increases the likelihood of successful account takeover without triggering security alerts.
Mitigation Recommendations
Organizations potentially affected by BigBear should immediately reset exposed passwords, revoke all active sessions, refresh authentication tokens, and enforce re-authentication for high-privileged accounts. It is recommended to enforce phishing-resistant authentication methods such as FIDO2/WebAuthn and implement Conditional Access policies requiring managed devices rather than relying on geo-location signals. CloudSEK has notified law enforcement and affected entities. The phishing infrastructure has been offline for nearly three weeks, but the administration panel remains online, so vigilance is advised.
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
Description
BigBear 2.0 is a phishing-as-a-service framework that has been used to bypass multi-factor authentication (MFA) at 258 organizations, stealing over 5,000 Microsoft 365 credentials. It operates as an adversary-in-the-middle proxy, intercepting passwords, MFA tokens, and session cookies to hijack authenticated sessions. The campaign targets Microsoft 365 users globally, leveraging geo-matched residential proxies to evade detection and custom JavaScript to disable stronger FIDO2/WebAuthn authentication methods. The phishing infrastructure remains partially active, with multiple affiliate operators receiving stolen credentials in real time. Organizations affected should reset passwords, revoke sessions, and enforce phishing-resistant authentication methods.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
BigBear 2.0 is a phishing-as-a-service (PhaaS) framework that uses an Evilginx2-based adversary-in-the-middle proxy to intercept Microsoft 365 credentials, including passwords, multi-factor authentication tokens, and session cookies, enabling attackers to bypass MFA and hijack user sessions. The service manages multiple VPS nodes and uses geo-matched residential proxies to avoid triggering Microsoft's security alerts. It also employs custom JavaScript to disable FIDO2/WebAuthn browser functionality, forcing victims to use weaker authentication methods. CloudSEK researchers accessed the control panel and found that the campaign compromised 258 distinct organizations, exfiltrating over 5,000 credential records and affecting over 3,300 unique victim IPs across 40+ countries. The phishing infrastructure has been offline for nearly three weeks, but the administration panel remains accessible. The service is leased to multiple affiliate operators who receive stolen credentials in real time via Telegram bots. CloudSEK has notified law enforcement and affected organizations.
Potential Impact
The campaign successfully bypassed MFA protections at 258 organizations, resulting in the theft of over 5,000 Microsoft 365 credentials, including plaintext passwords, MFA tokens, and session cookies. This allows attackers to hijack authenticated sessions and gain unauthorized access to Microsoft 365 services such as Exchange Online, Teams, SharePoint, OneDrive, and Entra ID. Compromise of these accounts can lead to exposure of sensitive emails and files, and potentially broader access through single sign-on integrations. The use of geo-matched proxies and disabling of phishing-resistant authentication methods increases the likelihood of successful account takeover without triggering security alerts.
Defensive Guidance
Organizations potentially affected by BigBear should immediately reset exposed passwords, revoke all active sessions, refresh authentication tokens, and enforce re-authentication for high-privileged accounts. It is recommended to enforce phishing-resistant authentication methods such as FIDO2/WebAuthn and implement Conditional Access policies requiring managed devices rather than relying on geo-location signals. CloudSEK has notified law enforcement and affected entities. The phishing infrastructure has been offline for nearly three weeks, but the administration panel remains online, so vigilance is advised.
Technical Details
- Classification
- {"confidence":0.8,"severitySource":"default","classifier":"rss-v2"}
Threat ID: 6a9ee135acd9273b49e62b98
Added to database: 09/07/2026, 16:07:17 UTC
Last enriched: 09/07/2026, 16:07:25 UTC
Last updated: 09/08/2026, 03:14:34 UTC
Views: 19
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.