#7
BleepingComputer
general
September 07, 2026 at 15:39 UTC
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
By Bill Toulas
AI Summary
The BigBear 2.0 phishing-as-a-service framework successfully bypassed MFA at 258 organizations and harvested over 5,000 Microsoft 365 credentials using adversary-in-the-middle token theft techniques. The scale and MFA-bypass capability of this platform underscores that TOTP and push-based MFA alone are insufficient against AitM proxy-based credential theft.
Relevance score: 84.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →