TechNewsReel
Live

BigBear 2.0 Phishing Service Bypasses MFA at 258 Microsoft 365 Organizations

A sophisticated Phishing-as-a-Service framework stole over 5,000 credentials by neutralizing multi-factor authentication and disrupting phishing-resistant security tools.

TechNewsReel Newsroom · September 7, 2026

A sophisticated phishing-as-a-service (PhaaS) operation known as BigBear 2.0 has compromised 258 organizations by bypassing multi-factor authentication (MFA) for Microsoft 365 users. The campaign highlights a growing trend in the commoditization of high-end cyberattack tools, allowing low-skill actors to execute complex breaches.

Researchers from CloudSEK uncovered the operation after gaining access to the service's administrative panel. The panel revealed 5,137 credential records, including 1,032 plaintext passwords and 4,148 session cookies. Most critically, the data confirmed 474 successful MFA bypasses. To evade detection, the attackers deployed a sprawling infrastructure consisting of 42 VPS nodes and residential proxies mapped to victim locations across 69 different countries.

The Mechanics of the Attack

BigBear 2.0 utilized an adversary-in-the-middle (AiTM) approach, leveraging the Evilginx2 framework to intercept data in real-time. Unlike traditional phishing, which simply steals a password, AiTM attacks sit between the user and the legitimate service. When a user enters their credentials and completes the MFA challenge, the attacker intercepts the resulting session cookie. This token allows the adversary to hijack the authenticated session, rendering the second factor of authentication ineffective because the attacker steals the proof of a successful login rather than guessing a code.

To further ensure success, the framework employed custom JavaScript designed to disrupt FIDO2 and WebAuthn functionality. By disabling browser features that support these phishing-resistant authentication methods, BigBear 2.0 forced users toward less secure login paths that the attackers could more easily manipulate.

Why This Matters

This campaign underscores a critical shift in the threat landscape: the professionalization of phishing. By offering these capabilities as a service, BigBear 2.0 removes the technical barrier to entry for executing AiTM attacks. The ability to systematically disable FIDO2 protections suggests that attackers are actively evolving to counter the very tools designed to stop them.

For the industry, this serves as a warning that standard MFA—such as SMS codes or push notifications—is no longer a sufficient silver bullet against determined adversaries. The success of this operation demonstrates that session theft is a primary vector for bypassing modern identity perimeters.

What's Next

Security professionals are now urged to move toward strict Conditional Access policies and fully phishing-resistant hardware keys. As PhaaS frameworks like BigBear 2.0 continue to integrate advanced evasion techniques, the focus is shifting toward zero-trust architectures that verify device health and location rather than relying solely on user credentials. Organizations are advised to monitor for unusual session cookie activity and unexpected logins from residential proxy ranges.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.