Feed›Social Engineering›BigBear Microsoft 365 phishing service bypassed MFA at 258 o...
Social EngineeringBleeping Computer
9.5 — CRITICAL

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

📅 7 September 2026 at 15:39 UTC📰 Bleeping ComputerView original source ↗
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

A phishing-as-a-service framework called BigBear was used to bypass multi-factor authentication at 258 organizations, stealing over 5,000 Microsoft 365 credentials through an Evilginx2-based adversary-in-the-middle framework.

⚙️Technical Details
Affected Systems
Microsoft 365
Attack Vectors
Evilginx2-based adversary-in-the-middle frameworkBigBear configuration called 'offy'
💥Impact Assessment
Severity: critical
Who Is at Risk
258 organizations with Microsoft 365 accounts
🛡️Recommended Actions
1Reset exposed passwords
2Revoke active sessions and refresh tokens
3Enforce phishing-resistant FIDO2/WebAuthn and use Conditional Access policies
📦Affected Products
Microsoft 365

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer ↗
← Back to feed