Executive Summary
In September 2026, the BigBear 2.0 phishing-as-a-service platform successfully compromised 258 organizations by bypassing multi-factor authentication on Microsoft 365 accounts. Using an Evilginx2-based adversary-in-the-middle framework across 42 VPS nodes, the operation captured over 5,000 credentials including 474 complete MFA bypasses, 1,032 plaintext passwords, and 4,148 session cookies. The service employed custom JavaScript to disable FIDO2/WebAuthn authentication and used geo-matched residential proxies across 69 countries to evade detection by Microsoft's security systems.
This incident highlights the evolving sophistication of phishing-as-a-service platforms that can defeat traditional MFA implementations, demonstrating the urgent need for phishing-resistant authentication methods and comprehensive identity security strategies as threat actors increasingly commercialize advanced bypass techniques.
Why This Matters Now
The BigBear incident exposes critical vulnerabilities in widely-deployed MFA systems, showing how commercialized phishing services can systematically bypass security controls at scale, making immediate adoption of phishing-resistant authentication and zero-trust principles essential for organizational security.
Attack Path Analysis
BigBear 2.0 phishing-as-a-service conducted adversary-in-the-middle attacks targeting Microsoft 365 authentication, using Evilginx2 proxies to intercept MFA-protected credentials and session cookies from 258 organizations. The attackers deployed geo-matched residential proxies across 42 VPS nodes, disabled FIDO2/WebAuthn protections via JavaScript manipulation, captured over 5,000 credentials including 474 complete MFA bypasses, and maintained persistent access through hijacked authentication sessions for ongoing Microsoft 365 environment compromise.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers deployed BigBear 2.0 phishing infrastructure using Evilginx2-based adversary-in-the-middle proxies positioned between victims and Microsoft's legitimate authentication servers, with custom JavaScript disabling FIDO2/WebAuthn to force weaker authentication methods
MITRE ATT&CK® Techniques
Phishing: Spearphishing Link
Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay
Steal Web Session Cookie
Modify Authentication Process
Valid Accounts: Cloud Accounts
Browser Session Hijacking
Proxy: External Proxy
Data from Information Repositories: SharePoint
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Multi-Factor Authentication for Administrative Access
Control ID: 8.4.2
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
DORA – Identification and Classification of ICT Risk
Control ID: Article 8
CISA ZTMM 2.0 – Identity Management and Authentication
Control ID: ID.AM-2
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
GDPR – Security of Processing
Control ID: Article 32
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
BigBear's MFA bypass targeting Microsoft 365 poses critical risks to banking operations, customer data protection, and regulatory compliance requirements.
Health Care / Life Sciences
Phishing-as-a-Service attacks compromising Microsoft 365 threaten patient data confidentiality and HIPAA compliance across healthcare organizations and research institutions.
Government Administration
Multi-factor authentication bypass attacks against Microsoft 365 infrastructure endanger sensitive government communications, citizen data, and national security operations.
Higher Education/Acadamia
Educational institutions face significant exposure to credential theft and session hijacking attacks targeting widely-deployed Microsoft 365 academic collaboration platforms.
Sources
- BigBear Microsoft 365 phishing service bypassed MFA at 258 organizationshttps://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/Verified
- Tracking BigBear 2.0: Evilginx2 Phishing Campaignhttps://www.cloudsek.com/blog/tracking-bigbear-2-0-evilginx2-phishing-campaignVerified
- CISA Phishing Guidancehttps://www.cisa.gov/topics/cybersecurity-best-practices/phishing-guidanceVerified
- Microsoft Security Response Center - Phishing Protectionhttps://msrc.microsoft.com/blog/tag/phishing/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain this Microsoft 365 credential theft campaign by limiting lateral movement through segmented cloud access and restricting egress paths for data exfiltration. While initial phishing compromise may still occur, the blast radius of subsequent lateral movement and persistent access would be significantly reduced.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Zero Trust architecture would likely limit the scope of initial access by enforcing identity-aware routing and device validation, potentially constraining compromised sessions to specific network segments rather than broad Microsoft 365 access
Control: Zero Trust Segmentation
Mitigation: Segmentation policies would likely constrain escalated privileges by limiting authenticated sessions to specific workloads and services, reducing the scope of Microsoft 365 resources accessible through hijacked tokens
Control: East-West Traffic Security
Mitigation: East-west enforcement would likely reduce lateral movement by constraining inter-service communication paths, limiting compromised accounts from accessing the full spectrum of Microsoft 365 and connected SSO applications
Control: Multicloud Visibility & Control
Mitigation: Visibility controls would likely constrain command and control operations by detecting and limiting abnormal traffic patterns from compromised accounts to external proxy infrastructure and communication platforms
Control: Egress Security & Policy Enforcement
Mitigation: Egress controls would likely reduce data exfiltration scope by constraining outbound data flows from compromised Microsoft 365 accounts, limiting bulk credential extraction to external Telegram bots and collection infrastructure
Residual impact would likely be constrained to specific network segments and workloads, significantly reducing the blast radius of business email compromise and data theft compared to unrestricted Microsoft 365 access
Impact at a Glance
Affected Business Functions
- Email Communications
- Document Collaboration
- Identity Management
- Single Sign-On Authentication
Estimated downtime: 3 days
Estimated loss: N/A
Over 5,000 Microsoft 365 credentials including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies affecting 3,331 unique victim IPs across 40+ countries. Compromised accounts provide access to email, files, and connected applications through single sign-on.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy Cloud Native Security Fabric (CNSF) with inline enforcement to detect and block adversary-in-the-middle proxy traffic patterns in real-time
- • Implement Zero Trust Segmentation with identity-based policies to limit Microsoft 365 session scope and prevent lateral movement across cloud services
- • Enable Multicloud Visibility & Control to detect anomalous authentication patterns and suspicious automation from residential proxy networks
- • Enforce Egress Security & Policy Enforcement to block unauthorized data exfiltration to external destinations and Telegram-based command channels
- • Activate Threat Detection & Anomaly Response capabilities to baseline normal authentication behaviors and alert on MFA bypass attempts and session replay attacks



