A phishing-as-a-service operation bypassed multifactor authentication at 258 organizations by stealing authenticated Microsoft 365 sessions, according to cybersecurity researchers at CloudSEK.
CloudSEK discovered BigBear 2.0 in June 2026 after gaining access to the operation’s administrative panel. The panel contained 5,137 records associated with 461 targeted organizations in more than 40 countries. The overlapping records included 4,148 session cookies, 1,032 plaintext passwords and 474 completed MFA-bypassed authentications.
The broader dataset includes 461 targeted organizations, but CloudSEK clarified, per BleepingComputer, that 258 had at least one completed MFA-bypass compromise. India, France, Saudi Arabia, New Zealand and Germany were among the most affected countries.
How BigBear gets around MFA
BigBear 2.0 is built around Evilginx2, an adversary-in-the-middle framework that sits between a victim and Microsoft’s legitimate login service.
Instead of trying to crack MFA, the attacker lets the victim complete it normally. The phishing proxy then captures the authenticated session cookie issued by Microsoft and can replay it, potentially giving the attacker access without another MFA prompt.
The service also uses residential proxies in 69 countries. By routing traffic through an IP address matching the victim’s location, attackers can make suspicious logins appear more normal and weaken location-based security controls.
CloudSEK also found custom JavaScript that disables FIDO2/WebAuthn functionality on phishing pages, potentially forcing users toward authentication methods that can be intercepted through the proxy.
A criminal service, not a one-off attack
BigBear’s infrastructure suggests the operation is designed for multiple customers rather than a single attacker. CloudSEK identified at least five affiliate operators receiving stolen information through separate Telegram bots.
The operation managed 42 VPS nodes during its observed lifetime, although CloudSEK said the operator had deleted 26 of them from the panel since late July. BleepingComputer reports that the administration panel remained online while the phishing infrastructure had been offline for nearly three weeks.
IT services and managed service providers were the most heavily represented sector, with 151 organizations identified in CloudSEK’s dataset. That raises the stakes because a compromised provider account can potentially expose systems belonging to multiple customers.
What organizations should change
The campaign shows why a successful MFA prompt cannot automatically be treated as proof that a session is trustworthy.
Organizations that detect related activity should revoke active sessions and refresh tokens, force affected users to reauthenticate, and reset exposed passwords. More importantly, phishing-resistant authentication such as FIDO2 or WebAuthn should be enforced rather than simply offered as an option.
Conditional Access policies that require managed or compliant devices can also reduce reliance on location signals, which BigBear’s residential proxies are designed to undermine. The larger takeaway is that MFA alone cannot protect an account when attackers can intercept and replay the authenticated session it creates.
Read more: Learn how new phishing tactics target Microsoft session tokens and authentication workflows, and which defenses can help organizations detect compromised access.





