BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
Executive Summary
BigBear 2.0, a phishing‑as‑a‑service framework, targeted 258 organizations, bypassing MFA to steal over 5,000 Microsoft 365 credentials. Attackers used compromised email accounts to send spear‑phishing emails, exploiting MFA bypass via credential harvesting. The operation demonstrates the effectiveness of phishing‑as‑a‑service and the need for stronger MFA enforcement.
Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-09-07T15:39:51+00:00 - Category: threat-intel
Original Description: A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. [...]
"Better to have loved and lost, than to have never loved at all."
— St. Augustine