# BigBear phishing operation reportedly bypassed MFA at 258 organizations

_Monday, September 7, 2026 at 11:39 AM EDT · Security · Latest · Tier 1 — Major_

![BigBear phishing operation reportedly bypassed MFA at 258 organizations — Primary](https://www.bleepstatic.com/content/hl-images/2026/05/15/MS365.jpg)

CloudSEK researchers said the BigBear 2.0 phishing-as-a-service operation bypassed multi-factor authentication at 258 organizations and collected more than 5,000 Microsoft 365 credential records.

The researchers said the operation used an Evilginx2-based adversary-in-the-middle proxy to intercept passwords and authenticated session cookies after victims completed MFA. CloudSEK reported 474 complete MFA-bypassed authentications, 1,032 plaintext passwords and 4,148 session cookies. It said it notified law enforcement and affected organizations; the administration panel remained online, though the phishing infrastructure had been offline for nearly three weeks.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/)

---
Canonical: https://techandbusiness.org/newswire/n449UUBl3fb6v2HB8Y_LjF
Retrieved: 2026-09-08T03:57:53.318Z
Publisher: Tech & Business (techandbusiness.org)
