A phishing-as-a-service platform called BigBear 2.0 has compromised Microsoft 365 accounts at 258 organizations, bypassing multi-factor authentication and stealing more than 5,000 credentials. The findings come from cybersecurity firm CloudSEK, which said it obtained administrator access to the service’s control panel and observed 42 virtual private server nodes, all configured to target Microsoft 365. The affected organizations are part of a broader dataset that included 461 entities, but CloudSEK confirmed that only 258 distinct organizations had at least one completed compromise involving an MFA bypass.
BigBear operates through a configuration named “offy,” which establishes a man-in-the-middle proxy between the victim and Microsoft’s legitimate authentication infrastructure. This approach allows attackers to intercept and reuse authenticated sessions, potentially exposing email, files, and other applications connected through single sign-on. Microsoft 365 is the company’s cloud productivity suite, which includes Exchange Online, Teams, SharePoint, OneDrive, and Entra ID authentication, making the service a high-value target for credential theft.
The platform also uses custom JavaScript to interfere with FIDO2 and WebAuthn authentication, disabling browser functionality that supports those phishing-resistant methods. By forcing targets toward weaker authentication options, BigBear increases its chances of success. Additionally, the service relies on geo-matched residential proxies for 69 countries, aligning the victim’s location with a residential IP address so Microsoft’s authentication servers do not flag the activity as suspicious. This technique helps the attacks evade detection based on standard location and IP reputation checks.
CloudSEK said it notified law enforcement and several affected organizations, and it included stolen credentials in responsible-disclosure reports. The administration panel for BigBear remains online, but the phishing infrastructure itself has been offline for nearly three weeks as of the report. The researchers did not specify which law enforcement agencies were contacted or how many organizations received direct notifications.
For organizations that may have been exposed, CloudSEK recommends resetting passwords, revoking active sessions, refreshing tokens, and forcing re-authentication for high-privileged accounts. The firm also advises enforcing phishing-resistant FIDO2 and WebAuthn methods and using Conditional Access policies that require managed devices rather than relying on geo-location signals. These steps are intended to limit the damage after an attacker has already obtained valid credentials.
The report notes that overall prevention scores can obscure what happens after initial access, because once attackers hold legitimate credentials, prevention effectiveness drops sharply. This context comes from The Blue Report 2026, which measures defenses technique by technique across 338 million simulations run in customer production environments. That data underscores the challenge of defending against AiTM phishing services like BigBear, which specifically target authentication flows rather than exploiting traditional software vulnerabilities.
More cybersecurity news from TechManNews.





