Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: bigbear (1 article)Clear

BigBear phishing service bypassed MFA at 258 organizations and disabled passkeys

Researchers at CloudSEK gained access to the control panel of BigBear, a phishing-as-a-service platform that defeated multi-factor authentication at 258 organizations and stole thousands of Microsoft 365 credentials. It uses an adversary-in-the-middle proxy based on Evilginx to sit between victims and Microsoft's real login, capturing passwords, multi-factor codes, and the session cookie, then replaying the cookie to hijack the already-authenticated session. The panel logged over 5,000 stolen records across 40-plus countries and is rented to multiple affiliates who receive stolen data through Telegram bots. Notably, it runs JavaScript that disables the browser's passkey support, forcing victims off phishing-resistant login onto weaker methods it can intercept.

Check
Enforce phishing-resistant passkeys with conditional access that requires managed devices, so attacker-in-the-middle kits cannot simply capture and replay session cookies or quietly downgrade users to weaker authentication.
Affected
Microsoft 365 organizations relying on passwords plus standard multi-factor authentication; BigBear steals the post-login session cookie to hijack accounts and can disable passkey support in the browser to force weaker login methods.
Fix
Adopt device-bound phishing-resistant authentication, require managed devices through conditional access, revoke sessions and refresh tokens on suspicion, monitor for impossible-travel and residential-proxy sign-ins, and train users on help-desk and login-page lures.