BigBear phishing crew nets thousands of Microsoft 365 credentials
- ID
- 22373
- Status
- summarized
- Published
- 08 Sep 2026, 9:26 PM
- Fetched
- 08 Sep 2026, 10:15 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/09/08/bigbear-phishing-crew-nets-thousands-of-microsoft-365-credentials/5294944
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 6.5
- Created
- 08 Sep 2026, 10:18 PM
- Tags
- Audience
- developerssaas_founders
What happened
CloudSEK researchers accessed the admin panel of BigBear 2.0, an active Evilginx2-based phishing-as-a-service operation, and found 5,137 stolen records tied to 461 organizations—including 1,032 plaintext passwords, 4,148 session cookies, and 474 fully MFA-bypassed Microsoft 365 sessions. The operation uses an adversary-in-the-middle proxy that relays victims through Microsoft's real login flow and captures the returned session cookie, allowing attackers to replay authenticated sessions without re-prompting MFA.
Why it matters
If your org relies on Microsoft 365 and Entra ID for SSO into cloud infrastructure or federated SaaS, MFA alone does not stop this attack—the session cookie is the prize. Practical response: enforce conditional access policies that bind sessions to device identity or specific IP ranges, shorten session token lifetimes, and monitor for impossible-travel or anomalous session usage rather than treating MFA enrollment as the finish line.
Discussion angle
Why MFA is necessary but insufficient against AITM phishing, and what conditional access controls actually stop session-cookie replay in a typical small-team M365 setup.