Social EngineeringBleeping Computer
9.5 — CRITICAL
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
A phishing-as-a-service framework called BigBear was used to bypass multi-factor authentication at 258 organizations, stealing over 5,000 Microsoft 365 credentials through an Evilginx2-based adversary-in-the-middle framework.
⚙️Technical Details
Affected Systems
Microsoft 365
Attack Vectors
Evilginx2-based adversary-in-the-middle frameworkBigBear configuration called 'offy'
💥Impact Assessment
Severity: critical
Who Is at Risk
258 organizations with Microsoft 365 accounts
🛡️Recommended Actions
1Reset exposed passwords
2Revoke active sessions and refresh tokens
3Enforce phishing-resistant FIDO2/WebAuthn and use Conditional Access policies
📦Affected Products
Microsoft 365
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
