Skip to content
Tech News
← Back to articles

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

read original get Yubico YubiKey 5 NFC Security Key → more articles
Why This Matters

BigBear 2.0 shows that phishing-as-a-service kits have made MFA bypass a commodity: for a subscription fee, affiliates can run adversary-in-the-middle proxies that steal session cookies after a victim passes MFA. With 258 organizations hit and thousands of credentials and cookies exfiltrated, it underscores that standard MFA is no longer sufficient protection for Microsoft 365 identity ecosystems.

Key Takeaways
Worth a Look

Yubico YubiKey 5 NFC Security Key — Adversary-in-the-middle kits like BigBear 2.0 work because push and code-based MFA can be relayed through a proxy — but FIDO2/WebAuthn hardware keys bind the login to the real domain, so a fake Microsoft 365 page gets nothing. The YubiKey 5 NFC plugs into USB-A or taps on a phone and works with Entra ID, Google, and password managers. It's a small, practical upgrade for anyone tired of phishable one-time codes.

See Yubico YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials.

Researchers at cybersecurity company CloudSEK gained administrator access to the control panel and found that the service managed 42 VPS nodes, all configured to target Microsoft 365 as part of the observed operation.

According to the researchers, the campaign uses an Evilginx2-based adversary-in-the-middle framework to intercept passwords and authenticated session cookies, allowing attackers to hijack accounts after victims complete the multi-factor authentication (MFA) process.

BigBear uses a configuration called “offy” that sets up a man-in-the-middle (AiTM) proxy between the victim and Microsoft’s legitimate authentication infrastructure.

This allows the attacker to capture credentials, including MFA, and session cookies and replay them through an API to hijack the victim’s authentication session.

Campaign timeline

Source: CloudSEK

Microsoft 365 is Microsoft's cloud productivity and identity ecosystem, incorporating services such as Exchange Online, Teams, SharePoint, OneDrive, and Entra ID authentication.

Compromising an authenticated Microsoft 365 session can expose email and files while potentially providing access to other applications connected through single sign-on.

According to CloudSEK, BigBear proved to be sufficiently successful to compromise hundreds of entities and capture thousands of cookies.

... continue reading