← Back to Feed

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

September 7, 2026 · BleepingComputer · Severity: MEDIUM

A phishing-as-a-service platform called BigBear was used to bypass multifactor authentication at 258 organizations. The service impersonates Microsoft 365 login pages and uses real-time credential harvesting combined with session cookie theft to bypass MFA protections.

Key Takeaways

  • The BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations, using advanced phishing kits to steal session tokens and credentials.
  • Organizations should implement phishing-resistant MFA methods like FIDO2 security keys and train users to recognize advanced phishing lures.
  • Organizations should review the full article for complete details and implement relevant security measures.
☕ Buy a Coffee