$ techbeacon▋
CVE & Exploits

Phishing-as-a-Service Tool Evades MFA, Compromising Thousands of Microsoft 365 Accounts Across Hundreds of Firms

Phishing-as-a-Service Tool Evades MFA, Compromising Thousands of Microsoft 365 Accounts Across Hundreds of Firms

A malicious service dubbed BigBear 2.0 has been linked to the theft of more than 5,000 Microsoft 365 credentials after circumventing multi-factor authentication (MFA) at 258 separate organizations.

The scheme operates as a phishing‑as‑a‑service platform, allowing cybercriminals to rent a ready‑made infrastructure that mimics legitimate Microsoft login pages. Victims receive crafted emails that appear to originate from trusted sources, prompting them to enter their credentials and the second‑factor code, which the service then captures in real time.

Security researchers who first uncovered the operation said the tool’s ability to sidestep MFA represents a notable escalation in phishing sophistication. By intercepting the one‑time passcode during the authentication flow, attackers can complete the login process without the user’s awareness, effectively nullifying one of the most widely recommended defenses against credential theft.

The breach affected a diverse set of entities, ranging from small businesses to larger enterprises that rely on Microsoft 365 for email, collaboration, and cloud storage. While the exact industries were not disclosed, the breadth of the impact underscores how pervasive the service has become among threat actors seeking quick, scalable access to corporate networks.

Microsoft has previously warned that MFA, while essential, is not immune to social engineering attacks that exploit the authentication process itself. The emergence of services like BigBear 2.0 highlights the need for layered security measures, including conditional access policies, user education, and continuous monitoring for anomalous sign‑in activity.

Experts suggest that organizations should review authentication logs for signs of repeated MFA prompts, enforce stricter verification methods such as hardware security keys, and consider deploying anti‑phishing solutions that can detect and block credential‑harvesting pages. As the phishing‑as‑a‑service market matures, defenders will need to adapt quickly to prevent similar large‑scale credential compromises in the future.

Vikas Thakur — Vikas covers DDoS attacks, botnet infrastructure, and network-layer threats. Hands-on experience with mitigation and traffic analysis, covers IoT botnets and infra-level attacks.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related