AI Weekly Malaysia

Back to items Summaries

BigBear phishing crew nets thousands of Microsoft 365 credentials

ID
22373
Status
summarized
Published
08 Sep 2026, 9:26 PM
Fetched
08 Sep 2026, 10:15 PM
Provider
The Register
Category
technology
Original URL
https://www.theregister.com/security/2026/09/08/bigbear-phishing-crew-nets-thousands-of-microsoft-365-credentials/5294944
Source URL
https://www.theregister.com/headlines.atom

Summary

Score
6.5
Created
08 Sep 2026, 10:18 PM
Tags
Audience
developerssaas_founders

What happened

CloudSEK researchers accessed the admin panel of BigBear 2.0, an active Evilginx2-based phishing-as-a-service operation, and found 5,137 stolen records tied to 461 organizations—including 1,032 plaintext passwords, 4,148 session cookies, and 474 fully MFA-bypassed Microsoft 365 sessions. The operation uses an adversary-in-the-middle proxy that relays victims through Microsoft's real login flow and captures the returned session cookie, allowing attackers to replay authenticated sessions without re-prompting MFA.

Why it matters

If your org relies on Microsoft 365 and Entra ID for SSO into cloud infrastructure or federated SaaS, MFA alone does not stop this attack—the session cookie is the prize. Practical response: enforce conditional access policies that bind sessions to device identity or specific IP ranges, shorten session token lifetimes, and monitor for impossible-travel or anomalous session usage rather than treating MFA enrollment as the finish line.

Discussion angle

Why MFA is necessary but insufficient against AITM phishing, and what conditional access controls actually stop session-cookie replay in a typical small-team M365 setup.

Top