BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

Summary

A phishing-as-a-service framework named BigBear 2.0 has successfully bypassed multi-factor authentication at 258 organizations. This framework has been used to steal over 5,000 Microsoft 365 credentials.

IFF Assessment

FOE

This article details a successful phishing campaign that bypassed MFA and stole credentials, representing a significant threat to organizations.

Defender Context

The emergence of sophisticated phishing-as-a-service tools like BigBear 2.0 highlights the ongoing threat to cloud-based credentials, even with MFA in place. Defenders should remain vigilant against advanced social engineering tactics and ensure robust endpoint detection and response capabilities to identify and mitigate such attacks.

Read Full Story →