BigBear 2.0 Microsoft 365 Phishing Campaign Bypasses MFA at 258 Organizations
A phishing-as-a-service operation called BigBear 2.0 has compromised 258 organizations by bypassing multi-factor authentication (MFA) and stealing more than 5,000 Microsoft 365 credentials, according to cybersecurity researchers.
Researchers at CloudSEK gained administrator access to the BigBear control panel and found that the service was managing 42 virtual private server (VPS) nodes. All of the observed infrastructure was configured to target Microsoft 365 accounts.
The campaign uses an Evilginx2-based adversary-in-the-middle (AiTM) phishing framework to intercept usernames, passwords, MFA responses, and authenticated session cookies. This enables attackers to hijack Microsoft 365 accounts even after victims successfully complete MFA.
BigBear relies on a configuration called “offy,” which places a malicious man-in-the-middle proxy between victims and Microsoft’s legitimate authentication services.
Using this setup, attackers can capture credentials and session cookies, then replay the stolen authentication data through an API to take over an active Microsoft 365 session.

Source: CloudSEK
Microsoft 365 accounts targeted by AiTM phishing
Microsoft 365 is Microsoft’s cloud productivity and identity ecosystem, including Exchange Online, Teams, SharePoint, OneDrive, and Entra ID authentication.
When attackers compromise an authenticated Microsoft 365 session, they may gain access to email, files, corporate applications, and other services connected through single sign-on.
CloudSEK said the BigBear phishing service has been effective enough to compromise hundreds of organizations and collect thousands of authentication cookies.
“The panel exfiltrated 5,137 credential records, including 474 full MFA bypass authentications, 1,032 cleartext passwords, and 4,148 session cookies. This affected 3,331 unique victim IPs in over 40 countries, and the operation is still ongoing as of this writing,” CloudSEK said in a report shared with BleepingComputer.
“The multi-user PhaaS panel has been leased to at least five affiliate operators identified through a live Telegram exfiltration bot, and each operator receives stolen credentials in real-time.”
Although the broader campaign targeted 461 organizations, CloudSEK determined that 258 organizations had experienced at least one confirmed MFA-bypass compromise.
BigBear interferes with phishing-resistant authentication
CloudSEK also found that BigBear uses custom JavaScript to interfere with FIDO2 and WebAuthn authentication. The code disables related browser features and attempts to force victims to use weaker authentication methods instead.
To make malicious sign-ins appear more legitimate, the platform uses geo-matched residential proxies across 69 countries. These proxies match a victim’s apparent location with a residential IP address, reducing the likelihood that Microsoft’s authentication systems will detect the activity as suspicious.

Source: CloudSEK
How organizations can respond to BigBear activity
CloudSEK said it notified law enforcement agencies and several affected organizations. The researchers also included the stolen credentials in a responsible disclosure report.
As of the report’s publication, the BigBear administrator panel remained online, although the associated phishing infrastructure had been offline for nearly three weeks.
Organizations that may have been targeted by BigBear 2.0 should immediately reset exposed passwords, revoke active sessions, invalidate refresh tokens, and require re-authentication for privileged accounts.
Security teams should also deploy Conditional Access policies that enforce phishing-resistant FIDO2 or WebAuthn authentication and require managed devices. These controls provide stronger protection than relying solely on geolocation-based risk signals.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
The Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com



