BigBear phishing service bypassed Microsoft 365 MFA and compromised accounts at 258 organizations

A phishing service called BigBear 2.0 was used to break into Microsoft 365 accounts at 258 organizations and steal thousands of credentials and session cookies. CloudSEK says the service uses an Evilginx2-based adversary-in-the-middle setup, meaning it sits between victims and Microsoft login pages to capture passwords, multifactor authentication results, and authenticated session cookies for account hijacking. Researchers found 42 VPS nodes, at least five affiliates, 5,137 credential records, 4,148 session cookies, and victims across 40+ countries.
Why it matters: Organizations using Microsoft 365 should treat this as an active account-takeover threat, especially where phishing-resistant authentication is not enforced. Defenders should reset exposed passwords, revoke sessions and refresh tokens, force re-authentication for privileged users, and prefer FIDO2/WebAuthn with device-based Conditional Access controls.

Sources

BigBear phishing crew nets thousands of Microsoft 365 credentials
2026.09.08 98% relevant
This is a direct update on the same BigBear 2.0 Evilginx2-based Microsoft 365 phishing operation, adding that researchers accessed the admin panel and found 5,137 stolen records tied to 461 organizations, including 1,032 plaintext passwords, 4,148 session cookies, 474 full MFA-bypassed sessions, affiliate use, Telegram delivery, residential proxies in 69 countries, and code that disables FIDO2/WebAuthn prompts.
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
Bill Toulas 2026.09.07 100% relevant
This article establishes a distinct phishing-as-a-service campaign, BigBear 2.0, with concrete scope, attack method, and victim counts rather than updating a previously tracked specific incident.
← Back to all stories