BigBear phishing kit bypassed Microsoft 365 MFA

Published September 7, 2026

BigBear 2.0 is a phishing toolkit that tricked users into bypassing Microsoft 365's multi-factor authentication and stole over 5,000 accounts. Attackers sent fake login pages to trick people into entering their credentials, even when MFA was enabled.

Report priority
Medium
Targets
Microsoft 365

How it works

  • Attackers used BigBear 2.0, a phishing toolkit, to send fake Microsoft 365 login pages to victims.
  • These pages mimicked the real Microsoft login but bypassed multi-factor authentication by tricking users into entering their credentials directly.
  • Once users entered their email and password, attackers captured those details and used them to access accounts without needing the second verification step.
  • The attackers targeted Microsoft 365 users by sending convincing emails that looked like official Microsoft notifications, urging users to click a link and log in.
  • The fake pages then captured credentials without alerting users to the trick.

What to do

If you or your organization received a phishing email from BigBear 2.0 and clicked on its fake Microsoft 365 login link, check your email for suspicious messages pretending to be from Microsoft, especially those asking you to log in or update your account. If you entered your credentials on a suspicious page, enable additional security alerts in your Microsoft 365 account settings to detect future login attempts. Microsoft 365 users who did not interact with the phishing link are not affected.

If you clicked on a suspicious link and entered your credentials, immediately change your Microsoft 365 password using a trusted device. Report the phishing attempt to Microsoft's security team or your organization's IT department. If you're unsure whether you were targeted, check your email for any unusual login alerts or suspicious activity in your Microsoft 365 account.

Technical details

Attackers sent an email to a victim pretending to be a Microsoft security alert. The email contained a link to a fake Microsoft 365 login page hosted on a compromised domain. When the victim clicked the link and entered their credentials, BigBear 2.0 captured the email and password, allowing attackers to bypass MFA and gain access to the victim's Microsoft 365 account.

A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials.