Back to Microsoft

Microsoft - Data Breach

moderateAnti-PrivacyData Breach

Executive Summary

A phishing service called BigBear 2.0 bypassed multi-factor authentication at 258 organizations and stole over 5,000 Microsoft 365 credentials by intercepting login sessions and authentication cookies. The service used man-in-the-middle tactics to capture credentials even after users completed MFA, then replayed session cookies to hijack accounts and access email, files, and connected applications. Researchers found the operation affected victims across 40+ countries and was being leased to m...

What Happened

A phishing-as-a-service platform called BigBear 2.0 used man-in-the-middle tactics to bypass multi-factor authentication and steal over 5,000 Microsoft 365 credentials from 258 organizations between an unspecified start date and September 2026. The service intercepted login sessions and authentication cookies even after users completed MFA, then replayed those session cookies to hijack accounts and access email, files, and connected applications. Cybersecurity firm CloudSEK discovered the operation after gaining access to BigBear's control panel and found the service was being leased to at least five different criminal operators who received stolen credentials in real time via Telegram.

Who Is Affected

Victims span more than 40 countries and include 3,331 unique IP addresses across 258 confirmed organizations that experienced successful MFA-bypass compromises. Anyone using Microsoft 365 services - including Exchange Online, Teams, SharePoint, OneDrive, and applications connected through single sign-on - at these organizations had their email, files, and potentially other connected accounts exposed. The attack specifically targeted users relying on non-FIDO2 authentication methods, as BigBear used custom JavaScript to disable stronger hardware-based authentication options.

Why It Matters

This breach demonstrates that multi-factor authentication alone is not sufficient protection against sophisticated phishing attacks that intercept session cookies rather than just passwords. The phishing-as-a-service model means even low-skilled criminals can now purchase access to advanced MFA-bypass capabilities, significantly lowering the barrier to conducting large-scale credential theft operations. The use of geo-matched residential proxies to avoid detection by Microsoft's security systems shows how attackers are evolving to evade cloud platform defenses that organizations increasingly rely upon.

What You Should Do

If you use Microsoft 365 at any organization, immediately enable FIDO2-compatible hardware security keys or Windows Hello for Business, as these phishing-resistant authentication methods cannot be bypassed by cookie replay attacks. Review your recent account sign-in activity through your Microsoft account security settings and revoke any suspicious sessions or unrecognized devices. Contact your organization's IT security team to determine if your company was affected and follow any specific remediation steps they provide, which may include password resets and re-authentication of all active sessions.

Summary generated from verified sources and reviewed before publication. How we summarize.

A phishing service called BigBear 2.0 bypassed multi-factor authentication at... - Microsoft | PrivacyWire