CuraSec

Act active

BigBear 2.0 PhaaS bypassed MFA at 258 orgs, stole 5,000 M365 credentials

2026-09-07 16:27 UTC · BleepingComputer · read the source ↗ #phishing-as-a-service#mfa-bypass#microsoft-365
  • Engineer — Plan: Active AiTM phishing at scale demonstrates that TOTP/push MFA is insufficient for M365; audit Conditional Access policies and plan a phishing-resistant MFA (FIDO2/passkeys) migration this quarter.
  • SOC/IR — Act: With 258 confirmed victim orgs, treat this as an active campaign: hunt Entra ID and unified audit logs for anomalous session token reuse, impossible-travel sign-ins, and OAuth consent grants since mid-2026.
  • Leader — Plan: A campaign compromising 258 organizations via MFA bypass is a concrete argument for budgeting phishing-resistant MFA; assess current MFA tier across the enterprise and bring a gap analysis to the next leadership review.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.