BigBear 2.0 completed MFA bypasses at 258 organizations and captured 5,137 credential records before researchers reached its control panel.

 

What happened

A phishing-as-a-service framework called BigBear 2.0 bypassed multi-factor authentication at 258 organizations and collected more than 5,000 Microsoft 365 credentials, BleepingComputer reported on September 7, 2026. Researchers obtained administrator access to the operation's control panel and found 42 virtual private servers, every one configured to target Microsoft 365. The panel recorded 5,137 credential records covering 474 completed MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, drawn from 3,331 unique victim addresses across more than 40 countries. A wider targeting dataset held 461 organizations, of which 258 had at least one successful bypass.

 

Going deeper

The framework builds on Evilginx2, an open-source toolkit that places an attacker's server between the victim and the genuine login page, relaying traffic in both directions while copying what passes through. A configuration the operators call "offy" handles that positioning against Microsoft's own authentication infrastructure. Credentials, the authentication code, and the session cookie all get captured together, then replayed through an application programming interface to take over the session the victim just opened. Compromising an authenticated Microsoft 365 session reaches email, files in SharePoint and OneDrive, Teams, and anything else connected through single sign-on. Five affiliate operators lease access to the panel, each receiving stolen credentials in real time through Telegram bots.

 

What was said

"The panel has exfiltrated 5,137 credential records," researchers wrote in the report shared with BleepingComputer, adding that the operation remained active at the time of writing. They notified law enforcement and several affected organizations, and included the captured credentials in responsible disclosure reports. The phishing infrastructure has been offline for nearly three weeks while the administration panel remains reachable.

 

In the know

Custom JavaScript in the kit interferes with FIDO2 and WebAuthn authentication, switching off the browser functionality that supports it so the target is pushed toward a weaker method. Nothing in that approach breaks the cryptography. It works because a second, phishable option remains available on the account, and removing the strong path leaves the user reaching for whatever else is enabled. The Cybersecurity and Infrastructure Security Agency recommends phishing-resistant methods precisely because one-time codes and push approvals can be relayed by an attacker positioned between the user and the service, in its guidance on implementing them. NIST states the objective as designing authentication that does not depend on the user detecting a phishing attack, which a downgrade prompt defeats by handing the decision back to the person.

 

The big picture

Geo-matched residential proxies covering 69 countries let the operators sign in from an address in the victim's own country, so Microsoft's authentication servers saw nothing unusual about the location. Conditional access policies built around unfamiliar countries or data center address ranges therefore produce no signal. What still works is requiring a managed, compliant device, which fails regardless of where the session appears to originate. For healthcare organizations running Microsoft 365 across clinical and administrative staff, the audit worth doing is narrow: establish which accounts have a phishable fallback still enabled alongside FIDO2, and whether conditional access rules currently lean on location rather than device state. Organizations that suspect exposure should reset affected passwords, revoke active sessions and refresh tokens rather than only changing credentials, and force re-authentication on privileged accounts.

 

FAQs

What is a downgrade attack in authentication terms?

An attacker manipulates the login process so a strong method appears unavailable, prompting the user to select a weaker alternative the account still permits. The strong method remains cryptographically sound throughout, and the account falls because a phishable option was configured alongside it.

 

How does an organization find its remaining fallback methods?

Through the identity provider's authentication methods policy, which lists what each user group can register and use. Reviewing it typically reveals that text message codes or authenticator app approvals stayed enabled during a passkey rollout, often deliberately as a recovery path.

 

Can fallbacks be removed entirely?

For most staff, yes, provided an alternative recovery route exists that does not rely on a phishable method, such as issuing a second hardware key or a supervised in-person reset. Break-glass administrative accounts need their own handling, since those are the accounts an attacker most wants.

 

Why does revoking sessions matter more than resetting passwords?

A stolen session cookie continues working after a password change, because it proves the user is already authenticated. Ending the compromise requires revoking active sessions and refresh tokens through the identity platform, which forces the attacker to authenticate again with credentials that no longer work.

 

Does a compromised Microsoft 365 account create HIPAA obligations?

Where the mailbox or connected storage holds protected health information, the covered entity conducts a breach risk assessment covering what was accessible and whether it was acquired. Audit logging configuration determines how confidently that question can be answered, which is why it matters before an incident rather than during one.