CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6545

As cited

Copy frozen at (site build).

threat intel

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

A phishing-as-a-service framework called BigBear 2.0 targeted 258 organizations to bypass multifactor authentication (MFA) and harvest more than 5,000 Microsoft 365 credentials. The campaign demonstrates the continued risk of credential theft despite MFA deployment.

Why it matters: Security teams managing Microsoft 365 should review authentication logs and phishing detection rules, as this attack bypassed MFA and affected hundreds of organizations across multiple sectors.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

A phishing-as-a-service framework called BigBear 2.0 targeted 258 organizations to bypass multifactor authentication (MFA) and harvest more than 5,000 Microsoft 365 credentials. The campaign demonstrates the continued risk of credential theft despite MFA deployment.

Why it matters: Security teams managing Microsoft 365 should review authentication logs and phishing detection rules, as this attack bypassed MFA and affected hundreds of organizations across multiple sectors.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary