BigBear 2.0 Bypasses Microsoft 365 MFA at 258 Organizations

BigBear 2.0 bypassed Microsoft 365 MFA at 258 organizations by stealing session cookies. Learn how the phishing service works and how to respond.

Sep 8, 2026
2 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

A phishing-as-a-service operation bypassed multifactor authentication at 258 organizations by stealing authenticated Microsoft 365 sessions, according to cybersecurity researchers at CloudSEK.

CloudSEK discovered BigBear 2.0 in June 2026 after gaining access to the operation’s administrative panel. The panel contained 5,137 records associated with 461 targeted organizations in more than 40 countries. The overlapping records included 4,148 session cookies, 1,032 plaintext passwords and 474 completed MFA-bypassed authentications.

The broader dataset includes 461 targeted organizations, but CloudSEK clarified, per BleepingComputer, that 258 had at least one completed MFA-bypass compromise. India, France, Saudi Arabia, New Zealand and Germany were among the most affected countries.

How BigBear gets around MFA

BigBear 2.0 is built around Evilginx2, an adversary-in-the-middle framework that sits between a victim and Microsoft’s legitimate login service.

Instead of trying to crack MFA, the attacker lets the victim complete it normally. The phishing proxy then captures the authenticated session cookie issued by Microsoft and can replay it, potentially giving the attacker access without another MFA prompt.

The service also uses residential proxies in 69 countries. By routing traffic through an IP address matching the victim’s location, attackers can make suspicious logins appear more normal and weaken location-based security controls.

CloudSEK also found custom JavaScript that disables FIDO2/WebAuthn functionality on phishing pages, potentially forcing users toward authentication methods that can be intercepted through the proxy.

A criminal service, not a one-off attack

BigBear’s infrastructure suggests the operation is designed for multiple customers rather than a single attacker. CloudSEK identified at least five affiliate operators receiving stolen information through separate Telegram bots.

The operation managed 42 VPS nodes during its observed lifetime, although CloudSEK said the operator had deleted 26 of them from the panel since late July. BleepingComputer reports that the administration panel remained online while the phishing infrastructure had been offline for nearly three weeks.

Advertisement

IT services and managed service providers were the most heavily represented sector, with 151 organizations identified in CloudSEK’s dataset. That raises the stakes because a compromised provider account can potentially expose systems belonging to multiple customers.

What organizations should change

The campaign shows why a successful MFA prompt cannot automatically be treated as proof that a session is trustworthy.

Organizations that detect related activity should revoke active sessions and refresh tokens, force affected users to reauthenticate, and reset exposed passwords. More importantly, phishing-resistant authentication such as FIDO2 or WebAuthn should be enforced rather than simply offered as an option.

Conditional Access policies that require managed or compliant devices can also reduce reliance on location signals, which BigBear’s residential proxies are designed to undermine. The larger takeaway is that MFA alone cannot protect an account when attackers can intercept and replay the authenticated session it creates.

Read more: Learn how new phishing tactics target Microsoft session tokens and authentication workflows, and which defenses can help organizations detect compromised access.

AA

Aminu Abdullahi is an experienced B2B technology and finance writer. He has written for various publications, including TechRepublic, eWEEK, Enterprise Networking Planet, eSecurity Planet, CIO Insight, Enterprise Storage Forum, IT Business Edge, Webopedia, Software Pundit, Geekflare and more.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.