BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

Executive Summary

BigBear 2.0, a phishing‑as‑a‑service framework, targeted 258 organizations, bypassing MFA to steal over 5,000 Microsoft 365 credentials. Attackers used compromised email accounts to send spear‑phishing emails, exploiting MFA bypass via credential harvesting. The operation demonstrates the effectiveness of phishing‑as‑a‑service and the need for stronger MFA enforcement.


Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-09-07T15:39:51+00:00 - Category: threat-intel

Original Description: A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. [...]

"Better to have loved and lost, than to have never loved at all."

— St. Augustine
Source: Bleeping Computer