Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

    September 7, 2026

    Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

    September 7, 2026

    We Are Going to Be Okay: A Three Year Anniversary Events Recap

    September 7, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
    News

    BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

    adminBy adminSeptember 7, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

    A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials.

    Researchers at cybersecurity company CloudSEK gained administrator access to the control panel and found that the service managed 42 VPS nodes, all configured to target Microsoft 365 as part of the observed operation.

    According to the researchers, the campaign uses an Evilginx2-based adversary-in-the-middle framework to intercept passwords and authenticated session cookies, allowing attackers to hijack accounts after victims complete the multi-factor authentication (MFA) process.

    BigBear uses a configuration called “offy” that sets up a man-in-the-middle (AiTM) proxy between the victim and Microsoft’s legitimate authentication infrastructure.

    This allows the attacker to capture credentials, including MFA, and session cookies and replay them through an API to hijack the victim’s authentication session.

    Campaign timeline
    Campaign timeline
    Source: CloudSEK

    Microsoft 365 is Microsoft’s cloud productivity and identity ecosystem, incorporating services such as Exchange Online, Teams, SharePoint, OneDrive, and Entra ID authentication.

    Compromising an authenticated Microsoft 365 session can expose email and files while potentially providing access to other applications connected through single sign-on.

    According to CloudSEK, BigBear proved to be sufficiently successful to compromise hundreds of entities and capture thousands of cookies.

    “The panel has exfiltrated 5,137 credential records – including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies – affecting 3,331 unique victim IPs across 40+ countries with the operation still active at the time of writing,” CloudSEK says in a report shared with BleepingComputer.

    “The multi-user PhaaS panel is leased to at least five affiliate operators identified through live Telegram exfiltration bots, each receiving stolen credentials in real time.”

    While 461 organizations appeared in the broader targeting dataset, CloudSEK clarified that 258 distinct organizations had at least one completed MFA-bypass compromise.

    CloudSEK has also found that BigBear uses custom JavaScript that interferes with FIDO2/WebAuthn authentication, disabling the browser functionality that accommodates it to force targets toward weaker authentication methods.

    To increase its effectiveness, the platform uses geo-matched residential proxies for 69 countries, matching the victim’s location with a residential IP address so that Microsoft’s authentication servers don’t flag the activity as suspicious.

    Configuring proxying from within the BigBear panel
    Configuring proxying in the BigBear panel
    Source: CloudSEK

    CloudSEK said it notified law enforcement and several affected organizations and included credentials in responsible-disclosure reports.

    At the time of writing, the administration panel remains online, while the phishing infrastructure has been offline for nearly three weeks.

    Organizations that were potentially affected by BigBear activity should reset exposed passwords, revoke active sessions, refresh tokens, and force re-authentication for high-privileged accounts.

    It is also advisable to enforce phishing-resistant FIDO2/WebAuthn and use Conditional Access policies that require managed devices rather than relying on geo-location signals.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleMagento StyleSmuggler zero-day exploited to deploy Linux backdoor
    admin
    • Website

    Related Posts

    News

    Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

    September 7, 2026
    News

    We Are Going to Be Okay: A Three Year Anniversary Events Recap

    September 7, 2026
    News

    Trezor data breach impact now reaches 81,000 customers

    September 7, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Our Picks

    BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

    September 7, 2026

    Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

    September 7, 2026

    We Are Going to Be Okay: A Three Year Anniversary Events Recap

    September 7, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.