Act
active
BigBear 2.0 PhaaS bypassed MFA at 258 orgs, stole 5,000 M365 credentials
- Engineer — Plan: Active AiTM phishing at scale demonstrates that TOTP/push MFA is insufficient for M365; audit Conditional Access policies and plan a phishing-resistant MFA (FIDO2/passkeys) migration this quarter.
- SOC/IR — Act: With 258 confirmed victim orgs, treat this as an active campaign: hunt Entra ID and unified audit logs for anomalous session token reuse, impossible-travel sign-ins, and OAuth consent grants since mid-2026.
- Leader — Plan: A campaign compromising 258 organizations via MFA bypass is a concrete argument for budgeting phishing-resistant MFA; assess current MFA tier across the enterprise and bring a gap analysis to the next leadership review.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.