$ techbeacon▋
Phishing

New Phishing‑as‑a‑Service Operation “BigBear 2.0” Hijacks Over 5,000 Microsoft 365 Accounts

New Phishing‑as‑a‑Service Operation “BigBear 2.0” Hijacks Over 5,000 Microsoft 365 Accounts

Security research firm CloudSEK has identified a fresh phishing‑as‑a‑service (PhaaS) campaign it calls BigBear 2.0, which has harvested more than five thousand Microsoft 365 credentials from victims worldwide.

The service operates on a subscription model, allowing cyber‑criminals to rent a ready‑made phishing kit that includes counterfeit login portals, email templates and backend infrastructure. By lowering the technical barrier, PhaaS outfits low‑skill actors with tools previously reserved for more sophisticated groups.

According to the analysis, the operation distributes lure emails that mimic legitimate Microsoft communications, directing recipients to look‑alike sign‑in pages. When users enter their corporate credentials, the data is captured and relayed to the operators, who can then reuse the accounts to infiltrate email, cloud storage, Teams and other SaaS services.

The scale of the breach—over five thousand compromised accounts—highlights the persistent risk to organizations that rely heavily on Microsoft 365 for daily operations. Access to a single account can provide a foothold for lateral movement, data exfiltration or further credential harvesting within an enterprise network.

Microsoft has not issued a public statement on the specific campaign, but security experts stress the importance of multi‑factor authentication, conditional access policies and continuous monitoring of sign‑in anomalies. Organizations are urged to educate users about suspicious emails and to enforce strong password hygiene.

BigBear 2.0 joins a growing list of PhaaS offerings that threaten to democratize credential theft. Researchers expect that as these services mature, the volume of compromised accounts will rise, making collaborative threat intelligence and rapid response essential for defending cloud‑based work environments.

Suresh Kanwar — Suresh reports on security breach post-mortems and enterprise incident response, breaking down attack timelines after major disclosures.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related