A phishing-as-a-service platform called BigBear 2.0 has successfully circumvented multi-factor authentication defenses to compromise more than 5,000 Microsoft 365 credentials across 258 organizations.
BigBear 2.0 represents a significant threat to enterprise security infrastructure. The service operates as a managed phishing framework, enabling attackers without specialized technical skills to launch sophisticated credential-harvesting campaigns.
The attack method focuses on Microsoft 365 environments, targeting the widely-used productivity suite. By bypassing MFA—a security control designed to prevent unauthorized access even when passwords are compromised—the service undermines a critical defense layer that many organizations rely on.
The scale of the breach indicates widespread deployment. Over 5,000 credentials stolen across 258 targets suggests the service has been actively used in multiple campaigns, likely sold or rented to various threat actors.
MFA bypass techniques typically involve intercepting authentication tokens or capturing credentials during the login process before MFA is triggered. Phishing-as-a-service platforms like BigBear 2.0 automate these attacks, lowering the barrier to entry for cybercriminals.
The discovery highlights evolving threats in the phishing landscape. Traditional phishing attacks rely on user error alone; advanced services combine automation with authentication bypass capabilities, creating layered threats that standard awareness training may not address.
Organizations using Microsoft 365 should review their security posture. Recommendations include:
- Implementing conditional access policies to restrict login attempts from unusual locations
- Deploying passwordless authentication where possible
- Using security keys for MFA instead of SMS or app-based codes
- Monitoring for suspicious authentication patterns
- Conducting security awareness training focused on sophisticated phishing tactics
Security vendors and Microsoft continue to track phishing-as-a-service operations. The emergence of BigBear 2.0 follows similar threats like Lapsus$ and other managed attack platforms that democratize cybercrime. Enterprise security teams should assume these services will continue evolving and adapting to bypass existing defenses.
A zero-day vulnerability called StyleSmuggler is being actively exploited across all versions of Magento and Adobe Commerce to install Linux backdoors on compromised systems.
Cryptocurrency hardware wallet maker Trezor revealed that an August data breach at logistics provider ShipMonk impacts 81,000 customers total, with an additional 67,000 U.S. customers newly affected.
Security researchers discovered that LG smart TVs continue recording audio and scanning local networks even when the display is powered down. The findings raise concerns about user privacy and device security.
ConnectWise has disclosed a new vulnerability in ScreenConnect remote access software without an immediate patch available. The company is offering temporary mitigation measures while preparing a fix for later this week.