ZeroHour
Story · 1 source · 1 articlefirst updated ()

CloudSEK infiltrates BigBear 2.0 phishing service that bypassed Microsoft 365 MFA at 258 organizations

highPhishing & fraudexploited in the wildimportance 74
What's new: All six reports (2026-09-07 to 2026-09-08) cover the same BigBear 2.0 story, so no new incident developments beyond prior coverage; this merge confirms panel telemetry figures and reconciles the organization count as 258 confirmed MFA-bypass compromises versus 461 organizations in targeting data. The separately reported Microsoft passkey-themed IT-helpdesk vishing campaign from the previous story…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

CloudSEK researchers gained admin access to the BigBear 2.0 control panel, an Evilginx2-based phishing-as-a-service platform that harvested 5,137 Microsoft 365 credential records — including 4,148 session cookies and 474 completed MFA bypasses — with 258…

CloudSEK researchers gained administrator access in June 2026 (per Cyber Security News and CSO Online) to the control panel of BigBear 2.0, an Evilginx2-based adversary-in-the-middle phishing-as-a-service platform run by an operator using the alias 'General Boss' and built around the 'offy' phishlet targeting Microsoft 365 (per Infosecurity Magazine). The panel held 5,137 credential records — 1,032 plaintext passwords, 4,148 session cookies, and 474 completed MFA-bypassed authentications — tied to 3,331 unique victim IPs in more than 40 countries. Sources frame organizational scope differently: BleepingComputer reports 461 organizations in targeting data with 258 distinct organizations having at least one completed MFA-bypass compromise (the 258 figure is also cited by DataBreaches.net), while Cyber Security News, Infosecurity Magazine, CSO Online, and The Register cite 461 organizations overall. The AiTM proxy intercepts credentials and authenticated session cookies that can be replayed into email, Teams, SharePoint, OneDrive, and connected SSO applications, potentially pivoting into Entra ID and federated SaaS; The Register notes MFA is bypassed by stealing sessions rather than defeated directly. Custom JavaScript interferes with (per BleepingComputer) or disables (per CSO Online and The Register) FIDO2/WebAuthn on phishing pages, steering victims toward phishable MFA, while geo-matched residential proxies in 69 countries evade Microsoft risk-flagging and defeat location-based Conditional Access checks. The operation ran 42 VPS nodes (mostly on Vultr, per Infosecurity Magazine), was leased to at least five affiliates delivering credentials in real time via Telegram bots, and was still active at reporting time; IT services and MSPs were the most targeted sector (151 of 461 organizations, per CSO Online), raising downstream supply-chain risk. CloudSEK advises resetting passwords, revoking sessions and tokens, and adopting phishing-resistant FIDO2/WebAuthn authentication.

  • CloudSEK gained administrator access in June 2026 (per Cyber Security News and CSO Online) to the BigBear 2.0 phishing-as-a-service control panel.
  • BigBear 2.0 is an Evilginx2-based adversary-in-the-middle platform run under the alias 'General Boss' using the 'offy' phishlet targeting Microsoft 365 (per Infosecurity Magazine).
  • Panel data showed 5,137 credential records: 1,032 plaintext passwords, 4,148 session cookies, and 474 completed MFA-bypassed authentications.
  • Stolen data was tied to 3,331 unique victim IPs across more than 40 countries.
  • Organizational scope: BleepingComputer reports 461 organizations in targeting data with 258 having at least one completed MFA-bypass compromise (also cited by DataBreaches.net); Cyber Security News, Infosecurity Magazine, CSO Online, and…
  • Captured session cookies can be replayed into email, Teams, SharePoint, OneDrive, and connected SSO apps, with potential pivoting into Entra ID and federated SaaS; per The Register, MFA is bypassed by stealing sessions rather than defeated…
  • Custom JavaScript interferes with (per BleepingComputer) or disables (per CSO Online and The Register) FIDO2/WebAuthn on phishing pages, pushing victims toward phishable MFA methods.
  • Geo-matched residential proxies spanning 69 countries evade Microsoft risk-flagging and defeat location-based Conditional Access checks.

Coverage timeline

  1. · 8d ago
    BleepingComputer· 72
    BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

    CloudSEK found the BigBear 2.0 phishing-as-a-service platform bypassed MFA at 258 organizations and captured over 5,000 Microsoft 365 credentials.