BigBear 2.0 Industrializes Microsoft 365 MFA Bypass

BleepingComputer says the BigBear 2.0 phishing-as-a-service kit was used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. The scale matters: this is not a one-off phish but a service built to turn live sign-ins into account access. The kit works by feeding a victim a fake-but-functional Microsoft 365 login flow and relaying the sign-in fast enough to capture the MFA result in the same session. Once that session is approved, the attacker can keep using it like the real user without needing the password or code again. For Microsoft 365 tenants, that means the exposure sits at the session layer: inbox takeover, internal phishing, and downstream account abuse can follow even when MFA is enabled. The reporting does not show what each victim lost, but it does show that session theft can be run repeatedly across many organizations at once.

Part of the PlainSec briefing for 2026-09-08

Every edition of this story: BigBear 2.0 Industrializes Microsoft 365 MFA Bypass

Sources