ZeroHour
DataBreaches.netpublished ()ingested Dissent

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

mediumPhishing & fraud exploited in the wildimportance 52
AI summary · glm-5.3-flash

The BigBear 2.0 phishing-as-a-service framework bypassed MFA to steal 5,000+ Microsoft 365 credentials across 258 organizations, CloudSEK researchers found.

CloudSEK researchers gained administrator access to the BigBear 2.0 control panel, finding the phishing-as-a-service operation ran 42 VPS nodes all configured to target Microsoft 365. The framework has been used to bypass multi-factor authentication at 258 organizations and harvest more than 5,000 credentials, indicating an active credential-theft campaign against enterprise tenants.

  • CloudSEK gained admin access to the PhaaS control panel
  • Operation ran 42 VPS nodes, all targeting Microsoft 365
  • MFA bypass yielded 5,000+ stolen credentials across 258 organizations
VendorsMicrosoft
Threat actorsBigBear 2.0
OrganizationsCloudSEK
Full article

Bill Toulas reports: A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. Researchers at cybersecurity company CloudSEK gained administrator access to the control panel and found that the service managed 42 VPS nodes, all configured to target Microsoft 365 as... Source

The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at databreaches.net.