BigBear 2.0 Microsoft 365 Phishing-as-a-Service (AiTM MFA Bypass)
First seen Sep 8, 2026 · Updated Sep 8, 2026
BigBear 2.0, a phishing-as-a-service (PhaaS) platform, has been used to compromise 258 organizations and steal over 5,000 Microsoft 365 credentials by bypassing multi-factor authentication via adversary-in-the-middle (AiTM) reverse-proxy techniques. The kit lowers the barrier to entry for large-scale credential phishing campaigns and has demonstrated broad reach across sectors relying on Microsoft 365 for identity and collaboration.
Technical Analysis
BigBear 2.0 operates as an AiTM reverse-proxy phishing kit that intercepts the full Microsoft 365 authentication flow, capturing session cookies and tokens after MFA completion rather than merely harvesting static credentials, allowing operators to hijack authenticated sessions and bypass MFA entirely. The service is sold to affiliates with ready-made phishing pages mimicking Microsoft login portals, evasion features (CAPTCHA challenges, bot filtering, geofencing) to evade automated security scanners, and dashboards for managing stolen credentials and cookies at scale. Because stolen Microsoft 365 sessions often grant access to connected services, mailboxes, SharePoint/OneDrive, and Entra ID-integrated applications, this creates a direct path to lateral movement and further credential harvesting or business email compromise. Organizations that use Microsoft 365 identities to authenticate AI agent frameworks, Copilot integrations, RAG pipelines pulling from SharePoint/OneDrive, or automation tools connected via Graph API are at risk of session/token theft enabling unauthorized agent access to sensitive corporate data and downstream API keys stored in mailboxes or connected apps.
Affected Systems
Microsoft 365 (Exchange Online, SharePoint, OneDrive, Teams), Microsoft Entra ID (Azure AD) authenticated sessions, any third-party or agentic applications using Microsoft 365 SSO/OAuth tokens
Indicators of Compromise
- Phishing kit name: BigBear 2.0
- AiTM reverse-proxy infrastructure mimicking Microsoft 365 login portals (specific domains/IPs not disclosed in source reporting)
- Stolen credential volume: 5,000+ Microsoft 365 accounts across 258 organizations
Remediation Steps
- 1
Enforce phishing-resistant MFA
Migrate from OTP/push-based MFA to FIDO2/WebAuthn hardware keys or certificate-based authentication that cannot be relayed by AiTM proxies.
- 2
Deploy conditional access policies
Use Entra ID Conditional Access to require compliant/managed devices and block sign-ins from unfamiliar locations or anomalous IP ranges.
- 3
Enable token protection
Turn on Microsoft Entra token protection (sign-in session bound to device) to prevent replay of stolen session cookies.
- 4
Monitor for session anomalies
Hunt for impossible travel, suspicious OAuth consent grants, and unusual mailbox rule creation indicative of BEC follow-on activity.
- 5
Revoke and rotate compromised sessions
For any suspected compromised account, revoke all refresh tokens/sessions, force password reset, and re-register MFA.
- 6
Audit connected applications and agent integrations
Review OAuth app permissions and any AI agent/automation tools using Microsoft 365 identities to ensure no unauthorized token reuse or excessive scopes.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.