BigBear Phishing Campaign Exposes Weaknesses in Microsoft 365 MFA Protection

A phishing-as-a-service operation known as BigBear 2.0 has reportedly compromised Microsoft 365 accounts at 258 organizations, highlighting how attackers are increasingly finding ways around traditional multi-factor authentication protections. Researchers investigating the operation found evidence that more than 5,000 Microsoft 365 credentials had been stolen, showing the scale at which these phishing campaigns can operate.

The investigation revealed that BigBear 2.0 was not simply a collection of ordinary phishing pages. The service was designed to support sophisticated attacks that could intercept information exchanged during the login process. Researchers were able to gain administrator-level access to the service’s control panel, giving them a closer look at how the infrastructure was organized and used.

Inside the control panel, investigators identified 42 virtual private server nodes. These servers were configured to target Microsoft 365 users, suggesting that the operation had been built to handle attacks against a large number of potential victims rather than relying on isolated phishing attempts. The infrastructure also indicates how phishing-as-a-service has evolved into a more organized criminal business model, where technical tools can be provided to attackers who may not have the skills to develop them independently.

image

One of the most concerning aspects of BigBear 2.0 is its ability to work around multi-factor authentication. MFA is widely regarded as an important layer of protection because it requires users to provide something beyond a password, such as a code, approval notification or security key. However, the presence of MFA does not automatically make an account immune to phishing.

The BigBear operation reportedly uses an adversary-in-the-middle technique. Instead of sending a victim directly to Microsoft’s genuine authentication service, the attacker places a malicious intermediary between the victim and the legitimate login system. The victim may still see a login process that looks convincing and may even complete the expected MFA step without realizing that an attacker is observing the authentication session.

This approach changes the nature of the attack. Traditional phishing often depends on stealing a username and password and then attempting to log into the account separately. With an adversary-in-the-middle setup, attackers can intercept information exchanged during the authentication process itself. This can include login credentials and authenticated session information.

BigBear 2.0 reportedly relies on technology based on the Evilginx2 framework to facilitate this process. Once a victim successfully authenticates, the attacker can potentially obtain session information that allows the account session to be taken over. In other words, the attacker may not need to defeat MFA directly. Instead, the goal is to exploit the authenticated session after the victim has already passed the security check.

The distinction is important because it demonstrates why security teams cannot treat MFA as a complete solution on its own. MFA remains significantly stronger than password-only authentication, but the type of MFA being used matters. Some authentication methods are more resistant to phishing than others, particularly when attackers are capable of intercepting sessions in real time.

The investigation also identified a configuration referred to as “offy” within the BigBear infrastructure. This configuration reportedly establishes a man-in-the-middle proxy between the victim and Microsoft’s legitimate authentication infrastructure. The arrangement allows the malicious service to sit between both sides of the communication while attempting to capture authentication information.

The stolen information can then potentially be used to take control of an authenticated session. This is particularly dangerous for Microsoft 365 accounts because a compromised account can provide access to email, documents, calendars, internal communications and other business resources. Depending on the victim’s privileges, attackers may also use a compromised account as a starting point for further attacks within an organization.

The number of affected organizations adds another layer to the concern. The reported 258 organizations show that these techniques are not limited to individual users or small-scale scams. A phishing service supported by a network of servers can allow criminals to target employees across different companies and industries while relying on an established technical framework.

The theft of more than 5,000 credentials also illustrates how attackers can benefit from volume. A campaign does not need every target to fall for the scam. Even a relatively small success rate can produce a substantial number of compromised accounts when thousands of users are targeted. Once those accounts are obtained, criminals can potentially use them for financial fraud, business email compromise, data theft or additional phishing campaigns.

For organizations using Microsoft 365, the incident reinforces the importance of combining MFA with other security controls. Security teams need to monitor unusual login behavior, investigate suspicious authentication sessions and pay attention to unexpected changes in account activity. Strong identity management and conditional access policies can also reduce the damage caused by compromised credentials.

Employee awareness remains important as well. Modern phishing attacks can be difficult to recognize because they may closely imitate legitimate authentication experiences. Users should be cautious about unexpected login requests, links received through unsolicited messages and authentication prompts that appear without a clear reason. An unexpected MFA request can sometimes be a warning sign that someone else is attempting to access an account.

Organizations can also reduce their exposure by adopting authentication methods designed to resist phishing. Hardware-backed security keys and other phishing-resistant authentication technologies can make it substantially harder for attackers to capture reusable authentication information through intermediary attacks. Regular security testing and monitoring can further help organizations identify weaknesses before criminals exploit them.

👁️ 44.5K+
Kristina Roberts

Kristina Roberts

Kristina R. is a reporter and author with a broad editorial focus, covering stories across arts and culture, entertainment, celebrity and influencer culture, business, music, technology, sports, lifestyle, and other topics shaping contemporary life. Her work spans both emerging trends and established industries, bringing together stories from across the worlds of media, creativity, innovation, and popular culture.

MORE FROM INFLUENCER UK

Newsletter

Sign up for Influencer UK news straight to your inbox!