BigBear phishing service bypassed MFA at 258 organizations
A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal over 5,000 Microsoft 365 credentials.

A sophisticated cyber threat has emerged involving a phishing-as-a-service (PaaS) framework known as BigBear 2.0. This platform has been actively deployed to bypass multi-factor authentication mechanisms across numerous corporate networks.
According to reports, the campaign has successfully targeted 258 organizations globally. Attackers leveraged the framework to compromise and steal more than 5,000 Microsoft 365 credentials, posing significant security risks to businesses.
What makes BigBear 2.0 particularly dangerous is its advanced capability to circumvent multi-factor authentication, a security layer that organizations traditionally rely on to protect sensitive user accounts from unauthorized access.
For the broader tech and business community, including regions like Central Asia and Eastern Europe, this incident highlights the evolving sophistication of cyber threats targeting cloud platforms like Microsoft 365, necessitating stricter security controls.
Security experts advise organizations to enhance their email security gateways, adopt phishing-resistant authentication methods where possible, and continuously train employees to recognize sophisticated social engineering tactics.



