BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
Summary
A phishing-as-a-service framework named BigBear 2.0 has successfully bypassed multi-factor authentication at 258 organizations. This framework has been used to steal over 5,000 Microsoft 365 credentials.
IFF Assessment
FOE
This article details a successful phishing campaign that bypassed MFA and stole credentials, representing a significant threat to organizations.
Defender Context
The emergence of sophisticated phishing-as-a-service tools like BigBear 2.0 highlights the ongoing threat to cloud-based credentials, even with MFA in place. Defenders should remain vigilant against advanced social engineering tactics and ensure robust endpoint detection and response capabilities to identify and mitigate such attacks.