Introduction
A new phishing‑as‑a‑service (PhaaS) offering, identified as BigBear 2.0, has demonstrated the ability to defeat multi‑factor authentication (MFA) on Microsoft 365 accounts. The campaign has compromised more than 5,000 credentials and affected 258 distinct organizations. The rapid adoption of the service signals a shift in how threat actors acquire valid credentials at scale.
What Happened
BigBear 2.0 was employed in a coordinated set of attacks that specifically targeted Microsoft 365 users. The service supplied phishing kits, infrastructure, and credential‑harvesting tools to its customers. By exploiting weaknesses in the MFA implementation, attackers obtained valid session tokens and passwords, allowing them to log in without triggering the second authentication factor. The operation resulted in the theft of over 5,000 Microsoft 365 credentials from 258 organizations.
Technical Details
The framework operates as a turnkey phishing solution. It hosts cloned Microsoft 365 login pages on attacker‑controlled domains and uses URL‑shortening or compromised legitimate sites to lure victims. Once a credential is entered, the platform automatically attempts to validate the password against the Microsoft authentication endpoint. If MFA is enabled, the service leverages a real‑time push notification relay that approves the request without user interaction. This technique, sometimes referred to as “MFA fatigue” or “push‑bombing,” overwhelms the user with multiple prompts until one is accepted, or it exploits misconfigurations that allow the attacker to bypass the second factor entirely.
The stolen data includes:
- Username (typically an email address)
- Password
- MFA session token or persistent cookie
No CVE identifiers were disclosed, indicating the bypass relied on procedural or configuration weaknesses rather than a software vulnerability in Microsoft 365 itself.
Who Is Affected
All organizations that rely on Microsoft 365 for email, collaboration, and identity management are potential victims. The confirmed incidents span 258 entities, ranging from small businesses to larger enterprises. Any tenant that permits MFA via push notifications without additional safeguards is exposed. Users who reuse passwords across services or who do not enforce conditional access policies are especially vulnerable.
Why It Matters
Credential theft at this scale undermines the core premise of MFA: that a stolen password alone is insufficient for access. When MFA can be neutralized, attackers gain persistent, privileged access to email, files, and internal communications. The breach of Microsoft 365 accounts often serves as a foothold for lateral movement, data exfiltration, and ransomware deployment. Moreover, the PhaaS model lowers the barrier to entry for less‑skilled actors, expanding the threat landscape dramatically.
Exploitation/Attack Information
The BigBear 2.0 service is actively exploited. Threat actors subscribe to the platform, receive ready‑made phishing templates, and obtain real‑time analytics on campaign performance. The service’s pricing model and ease of use encourage rapid iteration of phishing lures, making detection and response more challenging. Because the framework automates MFA bypass, attackers can harvest credentials faster than traditional phishing attempts that rely on manual credential verification.
Recommended Actions
- Enforce Conditional Access Policies – Require compliant devices, trusted locations, or additional verification methods (e.g., hardware tokens) for high‑risk sign‑ins.
- Implement MFA Prompt Limits – Configure Microsoft 365 to limit the number of push notifications per user per hour, reducing the effectiveness of push‑bombing attacks.
- Adopt Password‑less Authentication – Where possible, transition to FIDO2 security keys or Microsoft Authenticator’s password‑less flow.
- Monitor Sign‑In Anomalies – Enable Azure AD Identity Protection to flag impossible travel, unfamiliar locations, and atypical device usage.
- Educate End‑Users – Conduct regular phishing awareness training that includes examples of MFA fatigue attacks and emphasizes verification of push prompts.
- Review Third‑Party Integrations – Audit applications that have delegated permissions to Microsoft 365 and revoke unnecessary access.
- Deploy Zero‑Trust Architecture – Segment resources and enforce least‑privilege access to limit the impact of compromised accounts.
Immediate remediation should focus on tightening MFA controls and reviewing recent sign‑in logs for suspicious activity. Organizations that suspect compromise must force password resets for affected accounts and invalidate existing MFA tokens.
Conclusion
BigBear 2.0 illustrates how phishing‑as‑a‑service can evolve beyond credential harvesting to actively subvert MFA mechanisms. The campaign’s breadth—over 5,000 stolen Microsoft 365 credentials across 258 organizations—highlights the urgency of strengthening authentication flows and adopting a layered defense strategy. By applying the recommended mitigations, security teams can reduce the attack surface and mitigate the risk of similar PhaaS operations in the future.
Sources
- BleepingComputer: https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/