BigBear 2.0 phishing kit bypasses Microsoft 365 MFA
A phishing-as-a-service tool called BigBear 2.0 tricked Microsoft 365 users into handing over login sessions even when they used hardware security keys, by blocking the key prompt so victims fell back to weaker codes. CloudSEK researchers got into the operator's control panel and counted 461 targeted organizations across more than 40 countries, with 258 confirmed break-ins and over 5,000 stolen credentials and session cookies. The phishing servers appear to have gone offline in mid August, though the stolen logins are still out there.
- Started
- Aug 17, 2026
- Latest activity
- Aug 17, 2026
- Attributed to
- BigBear 2.0 phishing-as-a-service operation (alias "General Boss")Likely
- Where
- India, France, Saudi Arabia, New Zealand, Germany
- Sectors
- Technology, Energy, Multiple sectors
- Scale
- 258 confirmed compromises among 461 targeted organizations across more than 40 countries
Current status
The latest credible reports remain dated September 8, and checks through September 11 found no new activity or official closure.
Dormant: No new confirmed activity for a while, and nobody has called an official all clear.
Who is behind it
CloudSEK identified the alias and affiliate structure directly from the phishing panel it accessed; no law enforcement confirmation yet.
Impact
Attackers fully hijacked 474 Microsoft 365 accounts and captured over 5,000 credentials and session cookies, with the heaviest targeting hitting IT and managed service providers, whose access can cascade to their clients, plus SaaS, oil and gas, pharmaceutical and consulting firms.
What to do
Organizations should enforce hardware security keys as the only login option with no fallback to codes, texts, or push approvals, and check Microsoft 365 sign-in logs for sessions from unexpected locations or devices.
Timeline
-
Sep 8, 2026
Follow-up coverage repeated CloudSEK's findings. No report identified resumed operations, new victims, service restoration, or an official closure.
Dormantinfosecurity-magazine.com -
Sep 7, 2026
CloudSEK published findings from the BigBear 2.0 control panel, detailing 461 targeted organizations, 258 confirmed compromises, and over 5,000 stolen credentials.
Dormantbleepingcomputer.com -
Aug 17, 2026
The BigBear 2.0 phishing infrastructure appears to have gone offline, roughly three weeks before CloudSEK's report was published.
Dormanttechtimes.com
Sources
- BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations BleepingComputer Sep 7, 2026
- BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials Infosecurity Magazine Sep 8, 2026
- BigBear phishing kit steals Microsoft accounts with MFA SC World Sep 9, 2026
- BigBear 2.0 Hacked 258 Microsoft 365 Organizations by Disabling Hardware Security Keys Tech Times Sep 8, 2026
- BigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFA CSO Online Sep 8, 2026
- Microsoft 365 users hit by two major threat campaigns TechRadar Sep 8, 2026
Related reports
- BigBear phishing kit steals Microsoft accounts with MFA Sep 9, 2026
- BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft Sep 8, 2026
- BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials Sep 8, 2026
- BigBear 2.0 Bypasses Microsoft 365 MFA at 258 Organizations Sep 8, 2026
- BigBear phishing kit bypassed Microsoft 365 MFA Sep 7, 2026