BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
BLUF
BigBear 2.0 phishing service compromised MFA protections across 258 organizations, stealing over 5,000 Microsoft 365 credentials.
NEWS
Threat actors utilized the BigBear 2.0 phishing-as-a-service framework to circumvent multi-factor authentication mechanisms on Microsoft 365 platforms. The campaign resulted in credential theft affecting more than 258 distinct organizations, indicating widespread vulnerability to advanced phishing techniques.
Why I Care
This breach demonstrates that MFA is no longer a silver bullet against sophisticated phishing attacks, putting enterprise data and identity security at significant risk. Organizations relying solely on standard MFA without additional layers of protection face heightened exposure to account takeover and data exfiltration.
Next Steps
Security teams should immediately enforce phishing-resistant authentication methods like FIDO2 keys or certificate-based auth across all Microsoft 365 accounts. IT administrators must review sign-in logs for anomalies and implement Conditional Access policies to block legacy authentication protocols by the end of the quarter.
Source: BleepingComputer ·