Skip to main content
Emerging ThreatsMalware & Ransomware

Phishing Service BigBear Exposes 258 Firms to MFA Bypass

Office workers in background, foreground laptop screen blank and blurred.

"The panel has exfiltrated 5,137 credential records - including 474 complete MFA-bypassed authentications..." CloudSEK reported, summarizing an active phishing-as-a-service operation that targeted Microsoft 365 users worldwide.

How BigBear 2.0 operated

CloudSEK’s analysis found a phishing-as-a-service framework called BigBear 2.0 that relied on an Evilginx2-based adversary-in-the-middle (AiTM) approach to capture both credentials and authenticated session cookies. The service created a proxy between victims and Microsoft’s legitimate authentication endpoints, intercepting passwords, multi-factor authentication (MFA) tokens and session cookies. Attackers then replayed captured cookies through an API to hijack authenticated Microsoft 365 sessions after victims completed MFA.

Microsoft 365 is identified in the report as Microsoft’s cloud productivity and identity ecosystem, incorporating services such as Exchange Online, Teams, SharePoint, OneDrive, and Entra ID authentication. Compromising an authenticated Microsoft 365 session can therefore expose email and files and potentially provide access to other applications connected through single sign-on.

Scale and impact: 5,137 records, 258 organizations, 40+ countries

CloudSEK’s panel data showed the operation had exfiltrated 5,137 credential records in total, including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting 3,331 unique victim IPs across 40+ countries. While 461 organizations appeared in the broader targeting dataset, CloudSEK clarified that 258 distinct organizations had at least one completed MFA-bypass compromise.

The report noted the operation was still active at the time of writing. At that time the phishing infrastructure itself had been offline for nearly three weeks, but the administration panel remained accessible online.

Distribution model: multi-user PhaaS and real-time exfiltration

CloudSEK gained administrative access to BigBear’s control panel and observed a multi-user platform managing 42 VPS nodes configured to target Microsoft 365. The report describes BigBear as a multi-user PhaaS (phishing-as-a-service) panel that is leased to affiliates: "The multi-user PhaaS panel is leased to at least five affiliate operators identified through live Telegram exfiltration bots, each receiving stolen credentials in real time."

CloudSEK said it notified law enforcement and several affected organizations and included credentials in responsible-disclosure reports.

Technical evasion: the "offy" configuration, FIDO2 interference, and geo-matched proxies

BigBear used a named configuration called "offy" that set up the AiTM proxy between the victim and Microsoft’s authentication infrastructure. The platform also deployed custom JavaScript designed to interfere with FIDO2/WebAuthn authentication, disabling browser functionality that accommodates those phishing-resistant methods to steer targets toward weaker authentication options.

To reduce detection, BigBear used geo-matched residential proxies for 69 countries, matching a victim’s location with a residential IP address so Microsoft’s authentication servers would be less likely to flag the activity as suspicious. CloudSEK’s panel managed 42 VPS nodes across the observed operation.

What this means for technologists, affected enterprises, and end users

  • Technologists and security teams: CloudSEK recommends technical responses that address post-authentication risk — reset exposed passwords, revoke active sessions, refresh tokens, and force re-authentication for high-privileged accounts. The report also advises enforcing phishing-resistant FIDO2/WebAuthn and using Conditional Access policies that require managed devices rather than relying on geo-location signals.
  • Affected enterprises and procurement leaders: organizations in the observed set should prioritize session revocation and token refreshes for accounts suspected of exposure, and consider whether Conditional Access controls enforce device posture and phishing-resistant methods rather than just location-based signals.
  • End users and the general public: the report underscores that completing an MFA prompt does not guarantee safety if browsers or sessions can be proxied and cookies replayed; attackers in this operation captured MFA flows and session cookies to hijack accounts.

CloudSEK’s findings emphasize a specific operational point: once attackers possess valid credentials or session cookies, prevention effectiveness drops sharply. The report cites a broader measurement, the Blue Report 2026, noting that overall prevention scores can hide what happens after initial access — a reminder that detection and recovery actions matter as much as initial blocking. CloudSEK’s disclosure to law enforcement and affected organizations closes this chapter of reporting; the administration panel remaining online and the evidence of affiliate leasing leave open questions about successor operations and whether access logs will yield further attribution.

Read the original BleepingComputer story here: https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/