Security researchers identified a phishing-as-a-service operation, BigBear 2.0, that successfully circumvented multi-factor authentication (MFA) protections to infiltrate Microsoft 365 environments. The campaign targeted 258 organizations, resulting in the theft of more than 5,000 credentials for Microsoft’s collaboration suite.
What happened
BigBear 2.0 functioned as a subscription-based toolkit, enabling attackers to launch phishing attacks without requiring advanced technical expertise. The service exploited vulnerabilities in MFA implementations, allowing threat actors to harvest credentials even when additional authentication layers were enabled. The exact timeline of the attacks remains unclear, though the discovery was reported on 7 September 2026. No details were provided about the sectors or geographic distribution of affected organizations.
What we don’t know yet
The sources did not specify how the MFA bypass was achieved, whether the stolen credentials have been used in follow-up attacks, or if any of the compromised organizations have detected or mitigated the breaches. The identity of the operators behind BigBear 2.0 also remains undisclosed.
Companies mentioned
Automated pipeline · Security
Synthesized from 1 industry feed on 7 Sep 2026. Passed independent editor verification (score 85/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — New story No recent or in-pipeline article covers the BigBear Microsoft 365 phishing service bypassing MFA.
- Writing the article — Brief only thin sources; quick-read mode
- Writing the article — Draft created article_id=518 slug=bigbear-phishing-service-breached-258-orgs-via-mfa-bypass quick_read=1
-
Editor review — Approved
- Score: 85/100
- Factual grounding: The draft states the discovery was 'reported on 7 September 2026,' but the source does not explicitly confirm this as the discovery date. The source publication date is 7 September 2026, but this does not necessarily equate to the discovery date of the campaign.
- Style compliance: The standfirst ('Phishing-as-a-service tool stole 5,000 Microsoft 365 credentials') slightly overlaps with the title and could be more distinct. However, this is not a material issue.
- Audience relevance and notability: The story is highly relevant to hosting, cloud, and email professionals due to its focus on MFA bypasses in Microsoft 365 environments, a critical concern for enterprise security. However, the lack of sector or geographic details limits actionable context for operators.
- Generating reader Q&A — Generated 3 items
- Assigning hero image — Rejected library image #55: The candidate depicts a generic Microsoft 365 admin login interface, which is only tangentially related to the article's focus on phishing, MFA bypass, and credential theft. The alt text and context do not directly illustrate the phishing-as-a-service attack or security breach described in the article.
- Assigning hero image — Reused library image reused image #51
- Linking related stories — Linked 5 relations from 449 candidates
- Linking related stories — Linked 3 relations from 450 candidates
- Publishing — Published bigbear-phishing-service-breached-258-orgs-via-mfa-bypass
- Mastodon — Posted https://mstdn.social/@hostingpaper/117230854592557090




Discussion · coming soon
Be the first to join the thread when community discussion launches.