BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
Key Points:
- The phishing-as-a-service framework BigBear 2.0 has bypassed multi-factor authentication (MFA) at 258 organizations, stealing over 5,000 Microsoft 365 credentials by intercepting passwords and session cookies using an Evilginx2-based man-in-the-middle attack.
- Researchers at CloudSEK gained access to BigBear’s control panel, revealing the service managed 42 VPS nodes targeting Microsoft 365 and exfiltrated 5,137 credential records, including 474 fully bypassed MFA authentications and 4,148 session cookies across 40+ countries.
- BigBear employs custom JavaScript to disable FIDO2/WebAuthn authentication, forcing victims to use weaker methods, and uses geo-matched residential proxies to avoid detection by Microsoft’s authentication systems.
- The phishing infrastructure has been offline for nearly three weeks, but the control panel remains active; CloudSEK has notified law enforcement and affected organizations, recommending password resets, session revocations, and enforcement of phishing-resistant authentication methods.
- To mitigate risks, organizations are advised to implement FIDO2/WebAuthn, enforce Conditional Access policies requiring managed devices, and avoid relying solely on geo-location signals for authentication security.