<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations]]></title><description><![CDATA[<p dir="auto">A phishing-as-a-service (PhaaS) operation tracked as <strong>BigBear 2.0</strong> has been observed compromising Microsoft 365 environments at scale. According to telemetry, the campaign successfully bypassed multi-factor authentication (MFA) and harvested over <strong>5,000 credentials</strong> across <strong>258 organizations</strong>.</p>
<p dir="auto">The attack methodology relies on adversary-in-the-middle (AiTM) techniques to intercept session tokens. Below is a concise overview of the operational details and indicators.</p>
<ul>
<li><strong>Target scope:</strong> 258 unique organizations; more than 5,000 Microsoft 365 accounts compromised.</li>
<li><strong>Primary tactic:</strong> AiTM phishing to steal session cookies, allowing attackers to bypass MFA requirements.</li>
<li><strong>Payload focus:</strong> Microsoft 365 login pages, often using lookalike domains and urgency-based lures.</li>
<li><strong>Post-exploitation:</strong> Stolen sessions are typically used for data exfiltration and follow-up business email compromise (BEC).</li>
</ul>
<h3>Practical mitigation steps</h3>
<ul>
<li>Enforce <em>conditional access</em> policies that require device compliance or trusted locations, not just a one-time password.</li>
<li>Review sign-in logs for anomalous session activity, particularly where MFA was satisfied but geolocation or IP reputation appears suspicious.</li>
<li>Implement phishing-resistant MFA, such as <strong>FIDO2 security keys</strong>, where feasible.</li>
<li>Monitor for newly registered domains that mimic your organisation’s login portal.</li>
</ul>
<p dir="auto">Given the low cost of entry for such PhaaS platforms, it is likely this pattern will continue to evolve. Organisations relying solely on OTP-based MFA should treat these campaigns as a direct threat to their identity perimeter.</p>
<p dir="auto">Source: <a href="https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations" target="_blank" rel="noopener noreferrer nofollow ugc">Unknown</a></p>
<p dir="auto">Has your team reviewed sign-in logs for unusual session behaviour, or have you already moved to phishing-resistant MFA?</p>
]]></description><link>https://xploitlk.com/topic/251/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 06:10:35 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/251.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 07 Sep 2026 16:30:27 GMT</pubDate><ttl>60</ttl></channel></rss>