A phishing service called BigBear 2.0 was used to break into Microsoft 365 accounts at 258 organizations and steal thousands of credentials and session cookies. CloudSEK says the service uses an Evilginx2-based adversary-in-the-middle setup, meaning it sits between victims and Microsoft login pages to capture passwords, multifactor authentication results, and authenticated session cookies for account hijacking. Researchers found 42 VPS nodes, at least five affiliates, 5,137 credential records, 4,148 session cookies, and victims across 40+ countries.
Why it matters: Organizations using Microsoft 365 should treat this as an active account-takeover threat, especially where phishing-resistant authentication is not enforced. Defenders should reset exposed passwords, revoke sessions and refresh tokens, force re-authentication for privileged users, and prefer FIDO2/WebAuthn with device-based Conditional Access controls.
2026.09.08
98% relevant
This is a direct update on the same BigBear 2.0 Evilginx2-based Microsoft 365 phishing operation, adding that researchers accessed the admin panel and found 5,137 stolen records tied to 461 organizations, including 1,032 plaintext passwords, 4,148 session cookies, 474 full MFA-bypassed sessions, affiliate use, Telegram delivery, residential proxies in 69 countries, and code that disables FIDO2/WebAuthn prompts.
Bill Toulas
2026.09.07
100% relevant
This article establishes a distinct phishing-as-a-service campaign, BigBear 2.0, with concrete scope, attack method, and victim counts rather than updating a previously tracked specific incident.
← Back to all stories