BigBear 2.0 Phishing-as-a-Service Bypasses MFA at 258 Organizations

Executive Summary

Cybersecurity firm CloudSEK uncovered BigBear 2.0, a phishing-as-a-service platform that bypassed MFA on Microsoft 365, compromising over 5,000 credentials across 258 organizations. The service operated 42 VPS nodes targeting Microsoft 365, and researchers gained admin access to its control panel.


Intelligence Metadata - Source Publisher: DataBreaches.net - Published Date: 2026-09-07T17:24:23+00:00 - Category: threat-intel

Original Description: Bill Toulas reports: A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. Researchers at cybersecurity company CloudSEK gained administrator access to the control panel and found that the service managed 42 VPS nodes, all configured to target Microsoft 365 as... Source

"Fortune favours the brave."

— Virgil
Source: DataBreaches.net