BigBear phishing kit steals Microsoft accounts with MFA

Published September 9, 2026

A new phishing kit called BigBear 2.0 tricks Microsoft account users into giving up their passwords, even when they use two-factor authentication. Attackers send fake Microsoft login pages to steal credentials from over 3,300 people across 461 companies.

Report priority
Medium
Targets
Microsoft

How it works

  • Attackers send fake Microsoft login emails with links to phony Microsoft login pages.
  • These pages trick users into entering their Microsoft account credentials, even if they have two-factor authentication enabled.
  • The phishing kit then steals those credentials and uses them to access the victim's Microsoft account.

What to do

If you received a suspicious Microsoft login email with a link to a fake login page, or if you work at one of the 461 organizations listed in the report, check your Microsoft account for any unusual activity, such as unexpected logins or changes to your settings.

If you suspect you've been targeted, immediately change your Microsoft account password and enable additional security settings like Microsoft Authenticator or a hardware security key. Review your account activity in Microsoft's security dashboard and report any suspicious emails to your organization's IT team or Microsoft's support.

Technical details

Attackers send a fake Microsoft login email to a victim, which contains a link to a malicious website designed to look like the real Microsoft login page. When the victim enters their credentials, the phishing kit captures the login details and sends them to the attackers.

Researchers discovered more than 3,300 unique victims across 461 organizations.