Phishing kit 'BigBear' walked past Microsoft 365 logins at 258 companies
Researchers at CloudSEK found the rented service scooped up more than 5,000 Microsoft 365 credentials and 4,148 session cookies from victims in 40 countries.

Key points
- A rented phishing service called BigBear 2.0 broke into Microsoft 365 accounts at 258 organisations, according to researchers at CloudSEK.
- The panel had captured 5,137 credential records, including 474 logins where two-factor checks were fully bypassed, 1,032 plain-text passwords and 4,148 session cookies.
- Victims were spread across more than 40 countries and 3,331 unique IP addresses.
- The kit is leased to at least five criminal customers who receive stolen logins in real time through Telegram bots.
- The phishing sites have been offline for about three weeks, but the operators' control panel is still up.
A phishing operation called BigBear 2.0 has been quietly siphoning Microsoft 365 logins from hundreds of companies, and researchers say the kit is good enough to walk straight past two-factor security checks.
CloudSEK, the security firm that dug into it, managed to get administrator access to the crooks' own control panel. What they found inside was an industrial little business.
What is BigBear and how does it work?
BigBear is phishing-as-a-service: a ready-made phishing kit that criminals rent, the way a small business might rent accounting software. The operators handle the fake login pages and the plumbing. Their customers just log in and collect stolen accounts.
The kit uses a technique called adversary-in-the-middle, where the fake login page acts as a silent relay between the victim and the real Microsoft sign-in. When you type your password, it goes to Microsoft. When Microsoft asks for your two-factor code, you type that too. Everything works. You get logged in.
The trick is that the criminals were sitting in the middle the whole time, copying your password and, more importantly, the small file called a session cookie that Microsoft hands your browser to prove you've already signed in. Steal that cookie, replay it from another computer, and you are logged in as the victim without needing the password or the code again.
BigBear is built on an open-source tool called Evilginx2, which security testers use legitimately and criminals use less legitimately. CloudSEK counted 42 rented servers wired up to run the attack, all pointed at Microsoft 365.
How bad is the damage?
Bad, but bounded. CloudSEK told BleepingComputer the panel held 5,137 stolen credential records, of which 474 were complete two-factor bypasses. The rest were passwords and session cookies that are still useful to attackers.
Victims turned up in more than 40 countries. While 461 organisations showed up somewhere in the targeting data, 258 had at least one confirmed break-in.
| Item | Number |
|---|---|
| Organisations with confirmed break-ins | 258 |
| Total stolen credential records | 5,137 |
| Full two-factor bypasses | 474 |
| Session cookies captured | 4,148 |
| Rented servers running the kit | 42 |
| Criminal customers identified | 5+ |
The operators also rented residential internet connections in 69 countries so their logins to Microsoft would appear to come from the same city as the victim. That defeats one of Microsoft's simplest fraud checks.
One clever nasty touch: the kit runs custom JavaScript that switches off support for FIDO2 and WebAuthn, the strong hardware-key logins that this kind of attack cannot beat. With that route blocked, victims fall back to weaker codes the kit can steal.
Should ordinary Microsoft 365 users worry?
If your company uses Microsoft 365 and IT hasn't said anything, you personally don't need to panic. But if you clicked a Microsoft login link from an unexpected email in the last few months, tell your IT team. They can check whether your account shows up in the exposed data.
For administrators, CloudSEK's advice is straightforward: reset any passwords that may have leaked, kick out active sessions, force everyone with high-level access to sign in again, and move to hardware security keys where possible. Rules that only let company-managed laptops connect are more reliable than rules based on where the login appears to come from, because BigBear can fake the location.
The phishing pages have been down for roughly three weeks. The control panel, oddly, is still online.
Common questions
Does two-factor authentication still help?
Yes, for almost every other kind of attack. BigBear is designed specifically to defeat code-based two-factor. Hardware security keys using FIDO2 or WebAuthn are not fooled by this technique.
How would I know if my account was hit?
Watch for sign-in alerts from countries you don't visit, sent items you didn't send, or inbox rules you didn't create that quietly forward or delete messages. Report anything odd to your IT team quickly.



