← Back to Tech & Science

BigBear Phishing Framework Bypasses MFA at 258 Global Organizations

Tech & ScienceAI-Generated & Algorithmically Scored·

AI-generated from multiple sources. Verify before acting on this reporting.

A sophisticated phishing-as-a-service framework known as BigBear 2.0 has successfully bypassed multi-factor authentication defenses at 258 organizations, resulting in the theft of more than 5,000 Microsoft 365 credentials. The campaign, which targeted entities across more than 40 countries, exploited a vulnerability that allowed attackers to intercept passwords and authenticated session cookies even after victims completed security verification steps.

The operation, attributed to BigBear operators and their affiliate network, utilized a method designed to hijack accounts immediately following the multi-factor authentication process. By capturing valid session tokens, the attackers gained unauthorized access to corporate email systems and cloud applications without triggering standard intrusion alerts. The breach affects a diverse range of sectors, with compromised organizations spanning North America, Europe, Asia, and other regions.

Security experts note that the BigBear 2.0 framework represents an evolution in credential theft tactics. Unlike traditional phishing attempts that rely on users entering passwords into fake login pages, this operation intercepts the authentication flow itself. Victims receive what appears to be a legitimate Microsoft login prompt. Once they enter their credentials and approve a multi-factor authentication challenge, such as a mobile notification or biometric scan, the system captures the resulting session cookie. This allows the attackers to impersonate the user indefinitely, effectively rendering the second layer of security useless.

The scale of the operation suggests a coordinated effort by criminal groups monetizing access through a service model. Affiliates can reportedly purchase access to the framework to target specific industries or regions. The theft of over 5,000 credentials indicates that the campaign has been active for an extended period before detection, allowing attackers to establish persistent footholds within victim networks.

Organizations affected by the breach face immediate risks of data exfiltration, ransomware deployment, and further lateral movement within their internal systems. The compromise of Microsoft 365 accounts is particularly concerning given the platform's central role in enterprise communication and file storage. Administrators are advised to rotate credentials immediately and review authentication logs for signs of session hijacking.

As of September 7, 2026, the full extent of data accessed by the attackers remains unclear. It is unknown whether the stolen credentials were used to access sensitive intellectual property or financial records, or if they were sold on underground markets. Furthermore, the identity of the primary operators behind BigBear 2.0 has not been publicly disclosed. Law enforcement agencies and cybersecurity firms are currently investigating the scope of the intrusion and working to identify the infrastructure supporting the phishing-as-a-service platform. The incident highlights the growing sophistication of attacks designed to circumvent modern security protocols, leaving many organizations questioning the efficacy of current multi-factor authentication implementations.

Discussion

0 / 2000