Skip to main content
LetsDefend Infosec LetsDefend Infosec
  • Home
  • Services
    • VAPT
    • Compliance
    • Virtual CISO
    • GRC Platform
    • Consulting
    • Managed Security
    • Anti-Phishing
    • Awareness Training
    View all services
    Products
    • TrueVigil
    • CyberIntellect
    View all products
  • About us
  • Blog
  • Contact

← Back to insights

Threat Intelligence

BigBear 2.0 Phishing‑as‑a‑Service Bypasses MFA at 258 Organizations

8 September 2026 LetsDefend Infosec 4 min read

Introduction

A new phishing‑as‑a‑service (PhaaS) offering, identified as BigBear 2.0, has demonstrated the ability to defeat multi‑factor authentication (MFA) on Microsoft 365 accounts. The campaign has compromised more than 5,000 credentials and affected 258 distinct organizations. The rapid adoption of the service signals a shift in how threat actors acquire valid credentials at scale.

What Happened

BigBear 2.0 was employed in a coordinated set of attacks that specifically targeted Microsoft 365 users. The service supplied phishing kits, infrastructure, and credential‑harvesting tools to its customers. By exploiting weaknesses in the MFA implementation, attackers obtained valid session tokens and passwords, allowing them to log in without triggering the second authentication factor. The operation resulted in the theft of over 5,000 Microsoft 365 credentials from 258 organizations.

Technical Details

The framework operates as a turnkey phishing solution. It hosts cloned Microsoft 365 login pages on attacker‑controlled domains and uses URL‑shortening or compromised legitimate sites to lure victims. Once a credential is entered, the platform automatically attempts to validate the password against the Microsoft authentication endpoint. If MFA is enabled, the service leverages a real‑time push notification relay that approves the request without user interaction. This technique, sometimes referred to as “MFA fatigue” or “push‑bombing,” overwhelms the user with multiple prompts until one is accepted, or it exploits misconfigurations that allow the attacker to bypass the second factor entirely.

The stolen data includes:

  • Username (typically an email address)
  • Password
  • MFA session token or persistent cookie

No CVE identifiers were disclosed, indicating the bypass relied on procedural or configuration weaknesses rather than a software vulnerability in Microsoft 365 itself.

Who Is Affected

All organizations that rely on Microsoft 365 for email, collaboration, and identity management are potential victims. The confirmed incidents span 258 entities, ranging from small businesses to larger enterprises. Any tenant that permits MFA via push notifications without additional safeguards is exposed. Users who reuse passwords across services or who do not enforce conditional access policies are especially vulnerable.

Why It Matters

Credential theft at this scale undermines the core premise of MFA: that a stolen password alone is insufficient for access. When MFA can be neutralized, attackers gain persistent, privileged access to email, files, and internal communications. The breach of Microsoft 365 accounts often serves as a foothold for lateral movement, data exfiltration, and ransomware deployment. Moreover, the PhaaS model lowers the barrier to entry for less‑skilled actors, expanding the threat landscape dramatically.

Exploitation/Attack Information

The BigBear 2.0 service is actively exploited. Threat actors subscribe to the platform, receive ready‑made phishing templates, and obtain real‑time analytics on campaign performance. The service’s pricing model and ease of use encourage rapid iteration of phishing lures, making detection and response more challenging. Because the framework automates MFA bypass, attackers can harvest credentials faster than traditional phishing attempts that rely on manual credential verification.

Recommended Actions

  1. Enforce Conditional Access Policies – Require compliant devices, trusted locations, or additional verification methods (e.g., hardware tokens) for high‑risk sign‑ins.
  2. Implement MFA Prompt Limits – Configure Microsoft 365 to limit the number of push notifications per user per hour, reducing the effectiveness of push‑bombing attacks.
  3. Adopt Password‑less Authentication – Where possible, transition to FIDO2 security keys or Microsoft Authenticator’s password‑less flow.
  4. Monitor Sign‑In Anomalies – Enable Azure AD Identity Protection to flag impossible travel, unfamiliar locations, and atypical device usage.
  5. Educate End‑Users – Conduct regular phishing awareness training that includes examples of MFA fatigue attacks and emphasizes verification of push prompts.
  6. Review Third‑Party Integrations – Audit applications that have delegated permissions to Microsoft 365 and revoke unnecessary access.
  7. Deploy Zero‑Trust Architecture – Segment resources and enforce least‑privilege access to limit the impact of compromised accounts.

Immediate remediation should focus on tightening MFA controls and reviewing recent sign‑in logs for suspicious activity. Organizations that suspect compromise must force password resets for affected accounts and invalidate existing MFA tokens.

Conclusion

BigBear 2.0 illustrates how phishing‑as‑a‑service can evolve beyond credential harvesting to actively subvert MFA mechanisms. The campaign’s breadth—over 5,000 stolen Microsoft 365 credentials across 258 organizations—highlights the urgency of strengthening authentication flows and adopting a layered defense strategy. By applying the recommended mitigations, security teams can reduce the attack surface and mitigate the risk of similar PhaaS operations in the future.

Sources

  • BleepingComputer: https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/
#Phishing-as-a-Service #MFA Bypass #Microsoft 365 #Credential Theft #Threat Intelligence
Share:
On this page
Introduction What Happened Technical Details Who Is Affected Why It Matters Exploitation/Attack Information Recommended Actions Conclusion Sources

Have a question about your own security posture?

Related insights
Threat Intelligence
8 Sep 2026 5 min read

PEEP Toolkit Turns Chrome and Edge Into Post-Compromise Backdoors

Researchers have uncovered PEEP, a Chromium‑based post‑exploitation toolkit that masquerades as a bookmarks extension. It injects itself into Chrome and Edge profiles, bypasses store checks, and enables host command execution.

LetsDefend Infosec Read more
Threat Intelligence
8 Sep 2026 4 min read

Microsoft 365 and SaaS Data Theft Campaign Leveraging Help‑Desk Vishing and Token Hijacking

Threat hunters have uncovered a coordinated extortion operation that steals credentials from Microsoft 365 and other SaaS platforms. The group uses help‑desk vishing, in‑the‑middle token theft, and residential‑proxy sign‑ins to target executives, then threatens exposure unless paid.

LetsDefend Infosec Read more
Threat Intelligence
7 Sep 2026 4 min read

REVSTEALER Deploys Persistent Modules That Disable Defender and Launch Crypto Miner

Elastic Security Labs uncovered four new modules linked to the REVSTEALER Windows stealer. One module disables Windows Update and Microsoft Defender before starting a cryptocurrency miner, persisting after the original stealer removes itself.

LetsDefend Infosec Read more

Have a question about your own security posture?

LetsDefend Infosec LetsDefend Infosec

Practical cybersecurity for organisations that need clarity, confidence, and room to grow.

Explore

  • Services
  • Products
  • About us
  • Blog
  • Contact

Services

  • VAPT
  • Compliance
  • Virtual CISO
  • GRC Platform
  • Consulting
  • Managed Security
  • Anti-Phishing
  • Awareness Training

Get in Touch

info@letsdefend.in

+91 7859957803

2nd Floor Ved Plaza Complex,
Meghraj Road, Modasa,
Gujarat-383315

© 2026 LetsDefend Infosec. Built around better security decisions.
Privacy policy Terms of use

Developer tools are open. Please close them to keep browsing.

Ready when you are.

Send us a quick note about your goals, timeline, or current challenge, and we’ll come back with a considered next step.

We only use the information you provide to respond to this enquiry. No credentials or sensitive data are requested here.

Talk to an expert.

Tell us a little about your goals, timeline, or current challenge, and one of our experts will come back with a considered next step.

Preferred contact method

We only use the information you provide to respond to this request. No credentials or sensitive data are requested here.