BigBear phishing crew nets thousands of Microsoft 365 credentials

Summary

Researchers have gained access to the administrative panel of the BigBear phishing crew and discovered evidence of them stealing credentials from 461 organizations. The data indicates that thousands of Microsoft 365 credentials have been compromised.

IFF Assessment

FOE

This article details a successful phishing campaign that has compromised organizational credentials, representing a significant win for threat actors and a loss for defenders.

Defender Context

This incident highlights the ongoing threat of phishing attacks targeting cloud credentials, particularly Microsoft 365. Defenders should reinforce multi-factor authentication (MFA) and conduct regular user training on identifying and reporting phishing attempts. Monitoring for unusual login activity and credential stuffing can also help detect compromises.

Read Full Story →