BigBear 2.0 Phishing Campaign Bypasses MFA for 258 Organizations

BigBear 2.0 Phishing Campaign Bypasses MFA for 258 Organizations

First seen 7 Sep 2026, 17:34 UTC BleepingcomputerCloudsek 67.5

Article Content

Browse articles
ThreatCluster

The BigBear 2.0 phishing-as-a-service framework has been used to bypass multi-factor authentication (MFA) at 258 organizations, stealing over 5,000 Microsoft 365 credentials. Researchers from CloudSEK gained admin access to the control panel, which managed 42 VPS nodes configured to target Microsoft 365. The campaign employs an Evilginx2-based adversary-in-the-middle technique to intercept passwords and session cookies, allowing attackers to hijack accounts post-MFA. The operation has exfiltrated 5,137 credential records, including 474 MFA-bypassed authentications and 4,148 session cookies, affecting 3,331 unique IPs across over 40 countries. The panel is leased to at least five affiliate operators who receive stolen credentials in real time. Custom JavaScript injections disable FIDO2/WebAuthn MFA, forcing victims to use weaker authentication methods. As of now, the phishing infrastructure has been offline for nearly three weeks, but the admin panel remains active.

Key Points: • BigBear 2.0 has bypassed MFA for 258 organizations. • The campaign has exfiltrated over 5,000 Microsoft 365 credentials. • Custom JavaScript injections disable stronger authentication methods.

Ask AI about this cluster

Timeline

2026-06-01
Discovery of BigBear 2.0
CloudSEK's TRIAD discovered the BigBear 2.0 phishing framework and gained access to its control panel.
Cloudsek
2026-07-01
Active campaign observed
The BigBear phishing campaign was confirmed to be actively targeting organizations using Microsoft 365.
Cloudsek
2026-09-07
Reporting on BigBear impact
BleepingComputer reported that BigBear had compromised 258 organizations and stolen over 5,000 credentials.
Bleepingcomputer