type: incident ยท created: 2026-09-08 ยท updated: 2026-09-08 ยท tags: [incident, phishing, phaas, mfa-bypass, microsoft-365] ยท confidence: high ยท affected_sectors: [technology, finance, government] ยท au_impact: true
BigBear Microsoft 365 Phishing Service Bypassed MFA at 258 Organisations
Cybersecurity company CloudSEK, having gained administrator access to the service's own control panel, reports that a phishing-as-a-service platform it calls BigBear 2.0 has been used to bypass multi-factor authentication at 258 organisations, exfiltrating 5,137 Microsoft 365 records โ 474 complete MFA-bypassed authentications, 1,032 plaintext passwords and 4,148 session cookies โ across 3,331 unique victim IPs in more than 40 countries.
| Attribute | Detail |
|---|---|
| Scope | 258 organisations; 5,137 M365 records |
| Mechanism | Evilginx2-based adversary-in-the-middle proxy + custom JavaScript |
| Impact | Session hijack, MFA bypass |
| Source | CloudSEK (via BleepingComputer) โ Tier 2/4 |
The framework uses an Evilginx2-based adversary-in-the-middle proxy between the victim and Microsoft to capture passwords and authenticated session cookies for session hijack, using custom JavaScript in the delivery.