BigBear 2.0 Bypasses Microsoft 365 MFA at 258 Organizations
BigBear 2.0 is a phishing kit that tricks Microsoft 365 users into handing over their login credentials. Attackers then steal the session cookie to bypass multifactor authentication and take over accounts without extra prompts.
- Report priority
- Medium
- Targets
- Microsoft
How it works
- Attackers use Evilginx2, a phishing proxy that tricks users into logging into a fake Microsoft 365 page.
- When users enter their real credentials, the attacker captures the session cookie Microsoft issues after successful login.
- The attacker then replays that cookie to bypass multifactor authentication and gain access to the victim's account without needing to crack the MFA step.
- The kit also uses residential proxies in 69 countries to make login attempts appear legitimate by spoofing the victim's location.
What to do
If you or your organization used Microsoft 365 and received a suspicious email or link that looked like it came from Microsoft, check your email for unexpected login alerts in your Microsoft 365 security dashboard or account activity logs. If you see unfamiliar logins or unauthorized access attempts, immediately reset your Microsoft 365 password and enable additional security alerts in your account settings.
Review recent login activity in your Microsoft 365 security dashboard and report any suspicious activity to your organization's IT team or Microsoft support. Enable multi-factor authentication if it isn't already enabled and consider using a password manager to generate and store strong, unique passwords for your accounts.
Technical details
An attacker sends a phishing email with a link to a fake Microsoft 365 login page. When a victim enters their username and password, the attacker captures the session cookie Microsoft sends back. The attacker then uses that cookie to log into the victim's real Microsoft 365 account without triggering another MFA prompt.
A phishing-as-a-service operation called BigBear 2.0 exploited Microsoft 365's multifactor authentication (MFA) by stealing authenticated session cookies from victims. Researchers at CloudSEK uncovered the campaign in June 2026 after accessing its administrative panel, which contained 4,148 stolen session cookies, 1,032 plaintext passwords, and 474 successful MFA bypasses across 258 organizations in over 40 countries. The attack relied on Evilginx2, an adversary-in-the-middle framework that intercepts legitimate Microsoft login traffic, captures session cookies after MFA completion, and replays them to bypass further authentication.
The operation also used residential proxies in 69 countries to mask suspicious logins and disabled FIDO2/WebAuthn support on phishing pages, forcing victims into interceptable authentication methods. The infrastructure, including 42 VPS nodes and five affiliate operators, suggests a structured, recurring phishing service rather than a single attack.