474 Microsoft 365 Sessions Already Beat MFA. Here Is How BigBear Did It

Disclosure: Some links on this page are affiliate links. If you purchase through them, we may earn a commission at no extra cost to you. Full affiliate disclosure.

Threat Published September 9, 2026 · 8 min read · By Yongrui Sun
474 Microsoft 365 Sessions Already Beat MFA. Here Is How BigBear Did It
474 Microsoft 365 Sessions Already Beat MFA. Here Is How BigBear Did It

Most security advice still treats multi-factor authentication as the wall that stops phishing. It is not, and it has not been for several years. What MFA stops is the attacker reusing your password later. What it does not stop is an attacker standing between you and Microsoft while you type it.

CloudSEK obtained access to the admin panel of a phishing operation called BigBear 2.0 and read its own records rather than guessing from the outside. What was inside is the clearest published picture yet of how industrial credential theft actually runs: 5,137 records spanning 461 organisations, 1,032 plaintext passwords, 4,148 session cookies, and 474 confirmed sessions where MFA had been bypassed entirely.

Those 474 are the number worth sitting with. They are not attempts. They are finished jobs where the second factor was satisfied and the account was open anyway.

Editor’s take: Three things this guide doesn't cover but you should know: (1) document your actual workflow before buying; (2) ask the vendor for a 30-day pilot, not a 14-day trial; (3) set a hard review date — six months is the magic window. Tackle those after you finish the steps above.

Editor's Take

If one thing should come out of this incident, it is that SMS codes and push approvals are not phishing resistance, they are just a second thing an attacker can relay in real time. The fix is not more factors but a different kind: origin-bound credentials like passkeys or hardware keys, which simply cannot be replayed to a proxy site. MFA fatigue prompts are a design smell, not a control.

The Mechanism: A Proxy, Not a Fake Page

The old model of phishing was a counterfeit login form that harvested your password and then failed, because the code you generated seconds later was useless to an attacker who needed it immediately. Adversary-in-the-middle kits solved that by removing the counterfeit part.

BigBear runs Evilginx2, which acts as a reverse proxy. You receive a link, you land on what genuinely is Microsoft's login page, served through the attacker's domain. You type your password. Microsoft asks for your second factor and you supply it. Every one of those keystrokes is relayed to Microsoft in real time, and when Microsoft is satisfied it issues a session cookie — which comes back through the proxy, where the attacker keeps a copy.

Nothing was guessed. Nothing was cracked. The attacker watched a legitimate authentication happen and kept the receipt.

That cookie is the whole prize. Replaying it grants access to Outlook, calendar, Teams conversations, and everything in SharePoint and OneDrive without triggering another prompt. The 474 bypassed sessions were usable immediately.

They Turned Off the One Thing That Would Have Stopped Them

There is a class of authentication that defeats relay attacks completely: FIDO2 hardware keys and passkeys. These bind the credential cryptographically to the domain you are actually on. A proxied login presents the wrong origin, the key refuses to sign, and the attack fails with no user judgement required.

BigBear knew this, so its pages shipped custom JavaScript to disable FIDO2 and WebAuthn. With the strong option gone, users fell back to whatever remained: SMS codes and push approvals. Both are relay-friendly. You read a six-digit number off your screen and type it into the proxy, or you tap approve on a prompt you were already expecting.

If your organisation rolled out MFA and stopped there, this is the gap. The presence of a second factor is not the same as the presence of a phishing-resistant one.

Residential Proxies Make It Look Ordinary

The operation routed traffic through a residential proxy pool covering 69 countries. This does two jobs at once. Login attempts appear to originate from real home connections in plausible locations rather than a data centre, which helps them survive Microsoft's risk scoring. And the pool actively filtered out visitors arriving from data centres or VPNs, which is how researchers and scanners usually find these kits.

In practical terms: a security team that tried to visit the phishing page from their corporate network or a cloud VM often saw nothing at all. The kit hid from exactly the people looking for it.

This Is a Business With Customers

The panel was managed by an operator using the handle "General Boss" and rented out through a multi-user interface to at least five affiliate operators. Harvested credentials were pushed out in real time through a Telegram bot.

That structure matters more than the technical details, because it explains the volume. This is phishing-as-a-service: the person who builds the kit is not the person who writes the emails, and the person who steals the session is not the person who uses it. Specialisation is why a single operation reaches 461 organisations. Some infrastructure has since been taken down, but CloudSEK reported the operation was still active while it was being investigated.

What Actually Helps

Ordered by how much risk each one removes, not by how easy it is.

Worth checking today: whether your own email and phone number are already circulating in broker and stealer data. That is the raw material these operations use to make a phishing message specific enough to work.

Check PrivacyHawk pricing

For the user-side version of this — the specific tells in a login page and a prompt — our phishing identification guide walks through what to look at, and our password manager comparison covers the tools that refuse to autofill on a mismatched domain.

The Honest Read

MFA was never a wall; it was a speed bump that raised the cost of credential reuse. Kits like this one route around it by not reusing anything. The 474 sessions are not a failure of the users who typed their codes — they typed them into a real Microsoft page that asked for them.

The uncomfortable conclusion is that the defensive advice has to change shape. "Turn on MFA" was the right instruction in 2018. In 2026 the instruction is "turn on MFA that cannot be relayed," and anything less is a checkbox that looks like protection while providing considerably less of it than people assume.

YS
Founder & Editor

CyberPicks is published by Yongrui Sun. Every comparison is built from vendor documentation, published pricing, published specifications, and published independent-lab results. We do not run hands-on lab tests, and where a figure comes from a vendor or an independent testing lab we say which on the page.

Sources

How we compared

This account relies on published research into the technique and the phishing kit's documented behaviour.

Frequently asked questions

Does MFA stop Evilginx2 attacks?

SMS and push-notification MFA do not stop them. The proxy forwards your code to Microsoft in real time and captures the session cookie that comes back. Phishing-resistant factors such as FIDO2 hardware keys and passkeys do stop them, because the credential never leaves the device and is bound to the real domain.

What is adversary-in-the-middle phishing?

An attacker places a reverse proxy between you and the real login page. You see Microsoft's genuine interface and enter your password and second factor. Everything is relayed to Microsoft, which returns a valid session cookie that the attacker keeps and replays.

How many organisations were hit by BigBear?

CloudSEK found 5,137 records relating to 461 organisations in the BigBear 2.0 admin panel, including 1,032 plaintext passwords, 4,148 session cookies, and 474 confirmed sessions where multi-factor authentication had been fully bypassed.

Why did BigBear disable FIDO2?

Hardware keys and passkeys bind authentication to the real domain, so a proxied login fails. BigBear's custom JavaScript disabled FIDO2 and WebAuthn on the fake page so users fell back to SMS codes or push approvals, both of which a relay proxy can capture.

Is BigBear still active?

CloudSEK reported that parts of the infrastructure had been taken down but the operation was still active during the investigation. Stolen credentials were distributed in real time through a Telegram bot to at least five affiliate operators.

474 Microsoft 365 Sessions Already Beat MFA. Here Is How BigBear Did It — comparison snapshot
474 Microsoft 365 Sessions Already Beat MFA. Here Is How BigBear Did It — comparison snapshot