{"id":290,"date":"2026-09-20T16:18:37","date_gmt":"2026-09-20T16:18:37","guid":{"rendered":"https:\/\/bugleblast.com\/?p=290"},"modified":"2026-09-20T16:18:37","modified_gmt":"2026-09-20T16:18:37","slug":"microsoft-365-mfa-bypass-bigbear-phishing","status":"publish","type":"post","link":"https:\/\/bugleblast.com\/?p=290","title":{"rendered":"YOUR WORK MFA CAN STILL GET PROXIED! | BigBear PhaaS bypassed Microsoft 365 MFA at 258 orgs \u2014 lookalike pages steal the session"},"content":{"rendered":"<p>If your day job runs on Microsoft 365, \u201cI got the MFA prompt, so I\u2019m safe\u201d is not enough. BleepingComputer reported Sept. 7 that the BigBear 2.0 phishing-as-a-service (PhaaS) kit \u2014 built on Evilginx2 adversary-in-the-middle proxying \u2014 completed MFA bypasses at <strong>258 organizations<\/strong>.<\/p>\n<p>CloudSEK researchers who reached the control panel said the operation exfiltrated 5,137 credential records, including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies across 40+ countries. Custom JavaScript interferes with FIDO2\/WebAuthn to nudge victims toward weaker methods. Residential proxies matched to ~69 countries help the fake login look local to Microsoft\u2019s checks.<\/p>\n<p><strong>Frame it for normals:<\/strong> If you type your work email and password into a lookalike Microsoft page, the proxy can capture the session after you finish MFA \u2014 and then ride your cookie into Outlook, Teams, and OneDrive. Prefer phishing-resistant passkeys\/FIDO2 hardware where IT allows it. If you suspect you phished yourself, tell IT immediately, revoke sessions \/ sign out everywhere, and reset the password from a known-good device.<\/p>\n<p><strong>Sources:<\/strong> <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations\/\">BleepingComputer<\/a> (CloudSEK)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>BigBear PhaaS bypassed Microsoft 365 MFA at 258 orgs \u2014 lookalike pages steal the session<\/p>\n","protected":false},"author":1,"featured_media":289,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[1],"tags":[],"class_list":["post-290","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/bugleblast.com\/wp-content\/uploads\/2026\/09\/bb-bigbear-mfa-0920.jpg","_links":{"self":[{"href":"https:\/\/bugleblast.com\/index.php?rest_route=\/wp\/v2\/posts\/290","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bugleblast.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bugleblast.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bugleblast.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bugleblast.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=290"}],"version-history":[{"count":0,"href":"https:\/\/bugleblast.com\/index.php?rest_route=\/wp\/v2\/posts\/290\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/bugleblast.com\/index.php?rest_route=\/wp\/v2\/media\/289"}],"wp:attachment":[{"href":"https:\/\/bugleblast.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=290"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bugleblast.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=290"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bugleblast.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=290"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}