A phishing-as-a-service framework called BigBear 2.0 compromised 258 organizations and stole more than 5,000 Microsoft 365 credentials by bypassing multi-factor authentication through adversary-in-the-middle attacks.
The framework provides turnkey infrastructure for deploying AitM phishing attacks against Microsoft 365 users. Organizations that implemented MFA as a primary security control now face credential theft from a commercially available attack service that renders that protection ineffective.
BigBear 2.0’s Adversary-in-the-Middle Token Interception Defeats Multi-Factor Authentication
BigBear 2.0 operates as a phishing-as-a-service platform that handles the technical complexity of adversary-in-the-middle attacks for its customers. When a victim enters credentials on a BigBear-controlled phishing page, the framework relays those credentials to the legitimate Microsoft 365 authentication endpoint in real-time. The user completes MFA as normal, and BigBear intercepts the resulting session token before passing a fake error message to the victim.
The stolen session token provides full access to the compromised Microsoft 365 account without requiring the attacker to possess the user’s password or second factor. Session tokens remain valid for hours or days depending on organizational policy, giving attackers a window to access email, documents, and cloud resources before the token expires.
How 258 Organizations Lost Microsoft 365 Credentials Through a Single Phishing Service
The scale of the BigBear 2.0 campaign—258 organizations compromised through a single phishing service—demonstrates the democratization of sophisticated attack techniques previously limited to skilled threat actors. Phishing-as-a-service platforms lower the barrier to entry for credential theft by providing pre-built infrastructure, hosting, and evasion capabilities that individual attackers would struggle to develop independently.
Organizations affected by BigBear 2.0 likely include enterprises across multiple sectors. The more than 5,000 stolen credentials represent a mixture of employee and administrative accounts, with higher-privilege accounts posing the greatest risk for data exfiltration and lateral movement within compromised environments.
Microsoft 365 Defenses Beyond Traditional MFA Required to Counter AitM Phishing
Conditional Access Policies and Device Compliance Combat BigBear 2.0 Token Theft
Traditional MFA protects against password-only attacks but does not prevent session token theft when attackers control the authentication flow. Organizations should implement conditional access policies that enforce additional checks beyond initial authentication, such as device compliance requirements, trusted network restrictions, and continuous access evaluation that re-validates session tokens throughout their lifetime.
Security teams should monitor authentication logs for suspicious sign-in patterns characteristic of AitM phishing, including authentication attempts originating from residential proxy IP addresses, geographically inconsistent login sequences, and rapid token use following initial authentication. Residential proxies appear in BigBear and similar phishing services because they evade simple IP reputation checks that flag data center sources.
Stolen session tokens enable account takeover and data exfiltration even when the victim’s actual password and second factor remain secure. This disconnect—between credential protection and session protection—explains why MFA alone no longer constitutes sufficient defense against modern phishing. Organizations that treat MFA as a complete authentication solution rather than one component of a layered defense model face elevated risk from phishing services like BigBear 2.0.
The commercial availability of AitM phishing infrastructure shifts the threat landscape from targeted attacks by sophisticated actors to opportunistic campaigns accessible to any customer willing to pay for the service. Defenders should assume credential theft will occur despite MFA and design detection and response procedures around session-level anomalies rather than relying solely on authentication-time controls.
Phishing-as-a-service platforms like BigBear 2.0 package complex attack infrastructure into subscription offerings that require no technical expertise to operate. Customers receive ready-made phishing pages, domain hosting, SSL certificates that make fake sites appear legitimate, and automated token interception without needing to understand how AitM attacks function at a technical level. This commodification means organizations face attacks from a much broader range of threat actors than the relatively small population capable of building custom AitM infrastructure.
