• Salah Abdullah Al-attar - Editor-in-Chief

  • ع

BigBear phishing service bypasses MFA in 258 organizations on Microsoft 365..

A phishing platform disguised as a service, called BigBear 2.0, was used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials, according to CloudSEK researchers.


The investigators, who gained access to the control panel, found 42 VPS nodes targeting Microsoft 365. The tool employs an Evilginx2-style middleman design, acting as a proxy server between the victim and the legitimate Microsoft login pages to capture passwords, MFA proofs, and session cookies, which can then be reused to hijack authenticated sessions.