Dormant High impact Data breach Checked 11h ago

BigBear 2.0 phishing kit bypasses Microsoft 365 MFA

A phishing-as-a-service tool called BigBear 2.0 tricked Microsoft 365 users into handing over login sessions even when they used hardware security keys, by blocking the key prompt so victims fell back to weaker codes. CloudSEK researchers got into the operator's control panel and counted 461 targeted organizations across more than 40 countries, with 258 confirmed break-ins and over 5,000 stolen credentials and session cookies. The phishing servers appear to have gone offline in mid August, though the stolen logins are still out there.

Started
Aug 17, 2026
Latest activity
Aug 17, 2026
Attributed to
BigBear 2.0 phishing-as-a-service operation (alias "General Boss")Likely
Where
India, France, Saudi Arabia, New Zealand, Germany
Sectors
Technology, Energy, Multiple sectors
Scale
258 confirmed compromises among 461 targeted organizations across more than 40 countries

Current status

The latest credible reports remain dated September 8, and checks through September 11 found no new activity or official closure.

Dormant: No new confirmed activity for a while, and nobody has called an official all clear.

Who is behind it

CloudSEK identified the alias and affiliate structure directly from the phishing panel it accessed; no law enforcement confirmation yet.

Impact

Attackers fully hijacked 474 Microsoft 365 accounts and captured over 5,000 credentials and session cookies, with the heaviest targeting hitting IT and managed service providers, whose access can cascade to their clients, plus SaaS, oil and gas, pharmaceutical and consulting firms.

What to do

Organizations should enforce hardware security keys as the only login option with no fallback to codes, texts, or push approvals, and check Microsoft 365 sign-in logs for sessions from unexpected locations or devices.

Timeline

  1. Sep 8, 2026

    Follow-up coverage repeated CloudSEK's findings. No report identified resumed operations, new victims, service restoration, or an official closure.

    Dormantinfosecurity-magazine.com
  2. Sep 7, 2026

    CloudSEK published findings from the BigBear 2.0 control panel, detailing 461 targeted organizations, 258 confirmed compromises, and over 5,000 stolen credentials.

    Dormantbleepingcomputer.com
  3. Aug 17, 2026

    The BigBear 2.0 phishing infrastructure appears to have gone offline, roughly three weeks before CloudSEK's report was published.

    Dormanttechtimes.com

Sources

Related reports