Interestana
Home/News/BigBear Phishing Service Bypassed MFA at 258 Organizations
BleepingComputer3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

BigBear Phishing Service Bypassed MFA at 258 Organizations

A sophisticated phishing-as-a-service (PhaaS) framework, identified as BigBear 2.0, has been actively exploited to circumvent multi-factor authentication (MFA) protections, resulting in the compromise of at least 258 organizations and the exfiltration of over 5,000 Microsoft 365 credentials. This advanced threat actor has demonstrated a significant capability to bypass security measures that are widely considered robust, posing a substantial risk to businesses relying on Microsoft's cloud productivity suite. The BigBear 2.0 service operates by impersonating legitimate login pages, tricking users into entering their credentials and MFA codes, which are then relayed to the attackers in real-time. This technique, often referred to as a "man-in-the-middle" attack, allows threat actors to gain access to accounts even when MFA is enabled. The scale of the operation, affecting hundreds of organizations, highlights the pervasive nature of sophisticated phishing attacks and the ongoing challenges in defending against them. The stolen credentials could be leveraged for further malicious activities, including unauthorized access to sensitive data, financial fraud, and the deployment of ransomware. Microsoft 365 is a widely adopted platform for businesses globally, making such a breach a significant concern for corporate security. The attackers behind BigBear 2.0 have been observed to continuously evolve their tactics, techniques, and procedures (TTPs) to stay ahead of security defenses. This includes the use of sophisticated social engineering tactics and the development of custom tools to facilitate their operations. The reported success of BigBear 2.0 in bypassing MFA underscores the critical need for organizations to implement layered security strategies that go beyond standard authentication protocols. This includes continuous security awareness training for employees, robust endpoint detection and response (EDR) solutions, and proactive threat hunting. The specific number of organizations affected, 258, and the quantity of credentials stolen, over 5,000, provide concrete metrics of the campaign's impact. The ongoing nature of these attacks suggests that BigBear 2.0, or similar PhaaS operations, will continue to pose a threat to organizations worldwide. Security researchers are actively monitoring the activities of this threat group to develop effective countermeasures and provide timely intelligence to affected parties. The compromise of MFA, a cornerstone of modern cybersecurity, by such services represents a critical vulnerability that requires immediate attention from both technology providers and end-users.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next