Skip to main content
CyberSingle-sourceHighDevelopingFeatured
7.1

BigBear 2.0 phishing service bypasses MFA at 258 orgs, steals 5,000+ M365 credentials

A phishing-as-a-service framework, BigBear 2.0, has successfully bypassed multi-factor authentication at 258 organizations, compromising over 5,000 Microsoft 365 accounts. The attack leverages adversary-in-the-middle techniques to intercept session tokens, undermining MFA protections. This highlights a growing trend of credential theft despite MFA deployment, posing significant risk to enterprise security.

BleepingComputer1 day agoengCredibility 46%View source

Score Breakdown

Mosaic Score7.1
Confidence0.5
Significance0.8
Source credibility0.5
Source

Related signals

8 found