Security News

New Phishing Service 'BigBear 2.0' Bypasses MFA, Steals Over 5,000 Microsoft Logins

Infosecurity Magazine · 8 Sept 2026
Key Takeaway Australian SMBs, especially those using IT or managed service providers, should ensure MFA is paired with conditional access policies and session monitoring, since stolen login cookies can bypass MFA entirely.

Researchers at CloudSEK have identified a phishing-as-a-service (PhaaS) platform called BigBear 2.0 that has already stolen over 5,100 Microsoft 365 credential records from 461 organisations. The service is built on an adversary-in-the-middle framework, meaning it sits between a victim and a real login page to intercept both passwords and session cookies. This allows attackers to bypass multi-factor authentication by reusing stolen session data rather than needing a one-time code.

After gaining access to the platform's control panel, researchers found the operator running dozens of servers, real-time data theft via Telegram, and automated tools that let affiliates replay stolen cookies to hijack accounts. The most targeted countries included India, France, Saudi Arabia, New Zealand and Germany. Worryingly, IT service and managed service providers were the most frequently targeted sector, likely because compromising one provider can open the door to many of their clients through shared access to systems like Azure AD, RMM tools and password managers.

With stolen session cookies, attackers can access email, Teams, SharePoint, OneDrive and other connected business apps without needing to log in again, giving them a strong foothold for business email compromise, financial fraud and further data theft.

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.