READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

CloudSEK Finds BigBear 2.0 Phishing Service Bypassed MFA at 258 Microsoft 365 Organizations

CloudSEK Finds BigBear 2.0 Phishing Service Bypassed MFA at 258 Microsoft 365 Organizations
A phishing-as-a-service operation called BigBear 2.0 stole 5,137 Microsoft 365 credential records from 258 organizations by hijacking session cookies after victims completed MFA, according to CloudSEK. The kit also ran custom code to disable FIDO2 security key support in browsers, pushing users toward weaker, phishable login methods. This isn't a story about MFA failing. It's a story about companies treating MFA as the finish line when it's not.

A phishing-as-a-service platform called BigBear 2.0 compromised 258 organizations across more than 40 countries by stealing Microsoft 365 login sessions after victims completed multi-factor authentication, according to a report from cybersecurity firm CloudSEK.

CloudSEK says it gained access to the operation's administrative control panel in June 2026. Inside, researchers found 5,137 stolen credential records tied to 461 targeted organizations. That haul included 4,148 session cookies, 1,032 plaintext passwords, and 474 fully completed MFA-bypassed logins, CloudSEK reported. The firm says 3,331 unique victim IP addresses were affected.

CloudSEK told BleepingComputer the operation notified law enforcement and impacted organizations directly, including credentials in its disclosure reports. India, France, Saudi Arabia, New Zealand, and Germany were among the hardest-hit countries, according to esecurityplanet.

How It Worked

BigBear 2.0 runs on Evilginx2, an open-source adversary-in-the-middle (AiTM) framework. Instead of showing victims a fake login page, it inserts a proxy server between the victim and Microsoft's real authentication system, according to Bleeping Computer.

The victim types a real password and completes MFA normally. Microsoft authenticates them like usual. But once Microsoft issues the session cookie that keeps a user logged in, the proxy grabs it. As CSO Online and Computerworld both reported, an attacker can then reuse that cookie to access the account without ever tripping another MFA prompt.

"What BigBear 2.0 changes is accessibility and scale," said Akshat Tyagi, associate practice leader at HFS Research, in comments to CSO Online. "It packages AiTM phishing, residential proxies and automated cookie replay into a service that lowers the expertise needed to run these attacks."

Keith Prabhu, founder and CEO of Confidis, told CSO Online the operation's significance isn't just the technique, it's how BigBear 2.0 packages skills once reserved for advanced attackers into a service anyone can rent.

CloudSEK found the platform is leased to at least five affiliate operators, each pulling stolen credentials in real time through Telegram bots, according to Bleeping Computer. The operation ran 42 virtual private server nodes, though CloudSEK says 26 have been deleted from the panel since late July.

The FIDO2 Claim, Checked

Tech Times' headline framed this as BigBear 2.0 "disabling hardware security keys." That overstates what happened. CloudSEK's own findings, echoed across Bleeping Computer, esecurityplanet, and CSO Online, describe custom JavaScript that interferes with the browser's FIDO2/WebAuthn support, forcing a fallback to weaker, phishable authentication methods. It doesn't crack or defeat a physical security key.

The JRM360 Security blog draws that line directly: "That does not mean FIDO2 was defeated. Phishing-resistant authentication methods such as FIDO2 security keys and supported passkeys are specifically designed to resist this type of phishing." The real vulnerability is what happens when a user is allowed to fall back to SMS codes or app-based one-time passwords instead. That's the door BigBear 2.0 walks through.

Who Got Hit Hardest

IT services and managed service providers made up 151 of the identified organizations, the single largest sector, according to CloudSEK's data cited by esecurityplanet and CSO Online. A compromised MSP employee can potentially expose every client environment that provider manages.

CloudSEK also documented residential proxy infrastructure spanning 69 countries, matching an attacker's apparent location to the victim's real location. That defeats location-based Conditional Access checks that many companies rely on as a backstop, according to Computerworld.

What Comes Next

Bleeping Computer reported that as of its writing, BigBear 2.0's administration panel remained online even though the phishing infrastructure itself had been offline for nearly three weeks. CloudSEK's report itself notes the operation was "still active at the time of writing."

Law enforcement has been tipped off by CloudSEK, but whether they move to seize the panel and identify the five affiliate operators remains unclear. CloudSEK has recommended organizations that suspect exposure revoke active sessions, force password resets, and require phishing-resistant authentication for privileged accounts rather than offering it as one option among several.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
CSO OnlineBigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA
unknown
Bleeping ComputerBigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
unknown
news4hackersBigBear Microsoft 365 Phishing Campaign Bypasses MFA at 258 Organizations
unknown
Tech TimesBigBear 2.0 Hacked 258 Microsoft 365 Organizations by Disabling Hardware Security Keys - Tech Times
unknown
jrm360secBigBear Microsoft 365 Phishing Bypassed MFA | What Businesses Should Know | JRM360 Blog
unknown
ComputerworldBigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA
unknown
esecurityplanetBigBear 2.0 Bypasses Microsoft 365 MFA at 258 Firms