Cybersecurity

BigBear Phishing Service Bypassed Multi-Factor Authentication at 258 Organizations

Researchers found that the BigBear 2.0 phishing-as-a-service framework was used to hijack Microsoft 365 sessions after victims completed multi-factor authentication, and to steal thousands of credentials and cookies.

2026-09-07
3 min read
5 views
فريق تحرير certi.news
BigBear Phishing Service Bypassed Multi-Factor Authentication at 258 Organizations

A phishing-as-a-service operation called BigBear 2.0 was used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials, according to findings by cybersecurity company CloudSEK reported by BleepingComputer on September 7, 2026.

CloudSEK researchers were able to access the service’s control panel and found that it managed 42 VPS nodes configured to target Microsoft 365. The main phishing infrastructure had been offline for nearly three weeks when the report was prepared, but the administration panel remained accessible online, indicating that the operation had not been completely shut down.

How Did BigBear Bypass Multi-Factor Authentication?

The service relies on the Evilginx2 framework to carry out an adversary-in-the-middle (AiTM) attack. Rather than merely stealing the password, BigBear creates a proxy between the victim and Microsoft’s legitimate authentication infrastructure, then captures the password, authentication code, and session cookie after the user completes the MFA step.

The attacker can then reuse the cookie through an API to hijack the authenticated session. This means that MFA may have been successfully completed, but the resulting session itself ended up in the attacker’s possession. Because Microsoft 365 includes Exchange Online, Teams, SharePoint, OneDrive, and Entra ID, the impact of the compromised session may extend to email, files, and other applications connected through single sign-on.

Indicators of the Operation’s Scale

CloudSEK said that the control panel extracted 5,137 credential records, including 474 completed authentications with MFA bypassed, 1,032 plaintext passwords, and 4,148 session cookies, while identifying 3,331 unique victim IP addresses in more than 40 countries. The researchers also identified at least five affiliate operators renting access to the panel and receiving stolen data in real time through Telegram bots.

A total of 461 organizations were included in the broader targeting pool, but CloudSEK clarified that 258 distinct organizations had actually suffered a completed multi-factor authentication compromise. BigBear also used custom JavaScript to disable browser functions associated with FIDO2 and WebAuthn authentication, with the aim of pushing victims toward weaker authentication methods. The service also used residential proxies matching the victim’s geographic location in 69 countries to reduce the likelihood that Microsoft’s servers would detect unusual activity.

What Should Organizations Review?

CloudSEK said it had notified law enforcement and several affected organizations, and had included the credentials in responsible disclosure reports. For organizations that may have been targeted, recommended actions include resetting exposed passwords, revoking active sessions, renewing tokens, and enforcing reauthentication for privileged accounts.

The campaign demonstrates in practical terms that successful MFA alone is not sufficient when an attacker can intercept an authenticated session. CloudSEK therefore recommends enforcing phishing-resistant FIDO2 or WebAuthn and using Conditional Access policies that require managed devices, rather than relying solely on geographic-location signals. One point still requires human follow-up: the total and detailed record figures provided in the source do not reconcile mathematically, although the core compromise scope announced—258 organizations—is clearly specified.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news