databreaches.net 7 Sept 2026, 17:24 UTC

BigBear 2.0 Phishing Service Bypasses MFA at 258 Organisations

CyberSIXT Evidence Panel Source marked as original reporting

A phishing-as-a-service framework, branded as BigBear 2.0, has been used to bypass multi-factor authentication at 258 organisations and to steal more than 5,000 Microsoft 365 credentials. Researchers from CloudSEK report gaining administrator access to the framework’s control panel, discovering that the operation managed 42 virtual private server nodes all configured to target Microsoft 365.

They describe the campaign as employing an Evilginx2-based adversary-in-the-middle setup to intercept passwords and authenticated session cookies, enabling attackers to take control of accounts after the victim completes the MFA process.

The evidence presented indicates that the attackers could hijack sessions by harvesting credentials and session cookies during the authentication flow, undermining MFA protections. The operation’s scope—258 organisations affected and more than 5,000 credentials stolen—was observed through the researchers’ access to the BigBear 2.0 control panel and the 42 VPS nodes described.

The article notes that further details are available via a linked coverage piece, but the core disclosures provided here focus on the method ( Evilginx2 MITM framework), the scale (258 organisations, 5,000+ credentials), and the structural setup (42 VPS nodes targeting Microsoft 365). No specific mitigations or organisational responses are detailed within the provided content.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline