BigBear 2.0 Phishing Service Bypasses Microsoft 365 MFA to Impersonate Account Access
495/69 Wednesday, September 9, 2026
Researchers from CloudSEK have disclosed a report on BigBear 2.0, a phishing-as-a-service tool designed to steal Microsoft 365 login information. The service can capture passwords and session data after users complete multi-factor authentication (MFA). The investigation found 5,137 stolen credential records, including plaintext passwords and a large number of session cookies. This highlights that users remain at risk if they enter login information on phishing websites, even when MFA is enabled on their accounts.
The attack uses an adversary-in-the-middle (AiTM) technique by placing attacker-controlled infrastructure between the user and the legitimate Microsoft sign-in page. When victims enter their passwords and complete authentication, the system captures session cookies, which can then be used to impersonate the user and access accounts, email, and related services without requiring re-authentication. In addition, JavaScript was observed being used on phishing pages to interfere with FIDO2/WebAuthn functionality, forcing victims to switch to authentication methods that are less resistant to phishing. This represents an attempt to avoid the use of FIDO2/WebAuthn rather than a direct compromise of the security mechanism itself.
Administrators should enforce phishing-resistant authentication methods such as FIDO2/WebAuthn and configure access conditions that require organization-managed devices, rather than relying solely on login location. If an account is suspected to be affected, administrators should change the password, revoke related sessions and tokens, and require the user to sign in again to stop access using stolen session data.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.