BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

A Sophisticated Phishing Service Bypasses MFA at Hundreds of Organizations

A recent cybersecurity investigation has uncovered a highly sophisticated phishing-as-a-service (PhaaS) framework called BigBear 2.0, which has been used to compromise Microsoft 365 accounts at an astonishing 258 organizations worldwide. Researchers at CloudSEK discovered that the service exploited a vulnerability in multi-factor authentication (MFA), allowing attackers to hijack accounts even after victims completed the MFA process.

BigBear operates by setting up a man-in-the-middle (AiTM) proxy between the victim and Microsoft’s legitimate authentication infrastructure, using a configuration called “offy.” This allows the attacker to capture credentials, including MFA, and session cookies, which can then be replayed through an API to hijack the victim’s authentication session. The framework also uses custom JavaScript to disable FIDO2/WebAuthn authentication, forcing targets toward weaker authentication methods.

The BigBear service has been successful in compromising hundreds of entities, with thousands of credentials captured. CloudSEK estimates that 3,331 unique victim IPs across over 40 countries were affected by the operation, which is still active at the time of writing. The panel has exfiltrated a staggering 5,137 credential records, including 474 complete MFA-bypassed authentications and 1,032 plaintext passwords.

One of the most alarming aspects of BigBear is its use of geo-matched residential proxies for 69 countries, allowing it to evade detection by Microsoft’s authentication servers. This sophisticated technique involves matching the victim’s location with a residential IP address, making it nearly impossible to flag the activity as suspicious.

The implications of this attack are severe, as compromising an authenticated Microsoft 365 session can expose email and files while potentially providing access to other applications connected through single sign-on. Organizations affected by BigBear should immediately reset exposed passwords, revoke active sessions, refresh tokens, and force re-authentication for high-privileged accounts.

It is also essential for organizations to enforce phishing-resistant FIDO2/WebAuthn authentication and implement Conditional Access policies that require managed devices rather than relying on geo-location signals. This will help prevent attackers from using valid credentials to bypass security measures.

The success of BigBear highlights the ongoing threat posed by PhaaS frameworks, which can be easily leased or purchased by malicious actors. As cybersecurity professionals, it is crucial to stay vigilant and adapt our defenses to counter these sophisticated threats. By doing so, we can protect ourselves and our organizations from falling victim to such attacks.


Source: Bleeping Computer — 2026-09-07