BigBear Phishing Campaign Steals Thousands of Microsoft 365 Credentials

Security researchers breach the admin panel of the BigBear 2.0 phishing-as-a-service operation, revealing thousands of stolen Microsoft 365 credentials and active multi-factor authentication bypasses.

Security operations dashboard displaying threat intelligence data and phishing campaign analytics.
Security operations dashboard displaying threat intelligence data and phishing campaign analytics.

A sophisticated phishing operation known as BigBear 2.0 has harvested thousands of Microsoft 365 credentials and session cookies, impacting hundreds of enterprise organizations.

Key takeaways
  • CloudSEK researchers accessed the BigBear 2.0 admin panel and uncovered 5,137 records tied to 461 organizations.
  • The stolen haul included 1,032 plaintext passwords and 4,148 session cookies captured by Evilginx2 infrastructure.
  • Researchers identified 474 complete multi-factor authentication bypasses where active sessions were successfully hijacked.
  • Compromised Microsoft 365 accounts exposed sensitive enterprise data across email, Teams, SharePoint, and OneDrive.
In short

The BigBear phishing crew operated a phishing-as-a-service campaign targeting Microsoft 365 users, capturing over 5,000 records including plaintext passwords and session cookies that bypassed multi-factor authentication across hundreds of organizations.

A sophisticated cybercriminal enterprise has managed to harvest thousands of credentials and session tokens from corporate networks by deploying an advanced phishing kit against enterprise cloud environments. The operation, tracked as BigBear 2.0, leverages the Evilginx2 framework to intercept authentication flows and compromise user accounts without triggering standard security alerts. Security researchers recently gained direct visibility into the criminal infrastructure, exposing a massive haul of compromised corporate accounts across hundreds of distinct organizations globally.

According to researchers at CloudSEK, an investigation into the infrastructure revealed an active administrative dashboard containing thousands of individual victim records. The scope of the operation highlights the persistent vulnerability of cloud productivity suites to adversary-in-the-middle attacks that successfully bypass traditional multi-factor authentication controls.

How did the BigBear phishing crew steal Microsoft 365 credentials?

The BigBear 2.0 operation employs a phishing-as-a-service model built on top of Evilginx2, a specialized framework designed to perform adversary-in-the-middle attacks against web applications. By proxying legitimate authentication traffic through attacker-controlled servers, the phishing kit tricks victims into entering their login credentials while simultaneously capturing the resulting session cookies. This technique allows threat actors to bypass multi-factor authentication entirely because the victim has already completed the necessary security challenges on the fraudulent login portal, handing over an already-authenticated session token to the operators.

Security analysts who managed to infiltrate the threat actors' administrative panel uncovered a staggering amount of stolen data tied directly to enterprise users. The compromised logs contained thousands of individual records affecting hundreds of separate companies, demonstrating the industrial scale of the campaign. Instead of relying on crude credential harvesting pages, the operators utilized convincing replicas of corporate login screens to capture both plaintext passwords and valid session cookies in real time.

  • Researchers discovered 5,137 total records stored within the BigBear 2.0 administrative panel.
  • The compromised data spans 461 distinct corporate and government organizations.
  • The haul includes 1,032 plaintext passwords alongside 4,148 captured session cookies.
  • Analysts flagged 474 records as complete multi-factor authentication bypasses with active sessions.
"A hijacked Microsoft 365 account can expose email, calendars, Teams conversations, and files stored in SharePoint and OneDrive."

What are the risks of session cookie theft?

Stolen session cookies provide cybercriminals with unrestricted access to enterprise cloud environments, effectively turning a single compromised user into an internal beachhead. When attackers acquire a valid token rather than just a password, security controls like hardware security keys and authenticator app prompts become entirely irrelevant because the session is already established. This level of access grants the threat actor immediate entry into sensitive corporate communications, document repositories, and downstream cloud infrastructure without raising suspicion from identity providers.

Once inside a cloud tenant, malicious actors can exploit the permissions of the hijacked account to orchestrate business email compromise, launch internal phishing campaigns, or exfiltrate proprietary data. Depending on the privileges assigned to the specific user, attackers can pivot deeper into the organization, potentially reaching Entra ID management tiers or connected software-as-a-service applications. Because the BigBear operation remained active during the investigative phase, affected organizations faced immediate risks of data theft and lateral movement across their enterprise networks.

What to watch next

Defenders and security teams monitoring cloud infrastructure should track specific operational indicators to mitigate ongoing threats from advanced phishing kits. Keep a close eye on the following development areas over the coming months:

  • Updates from cloud security vendors regarding new behavioral detection rules for Evilginx2 proxy domains.
  • Adoption rates of token protection policies within Microsoft Entra ID to invalidate stolen session cookies.
  • Enforcement of phishing-resistant hardware tokens like FIDO2 keys across high-privilege enterprise accounts.

Frequently asked

What is the BigBear phishing operation?

BigBear is a phishing-as-a-service operation utilizing the Evilginx2 framework to target Microsoft 365 users, capturing plaintext passwords, session cookies, and bypassing multi-factor authentication.

How does Evilginx2 bypass multi-factor authentication?

Evilginx2 acts as an adversary-in-the-middle proxy between the victim and the legitimate login page, capturing valid session cookies after the user successfully completes their multi-factor authentication challenge.

What data was found in the BigBear admin panel?

Security researchers at CloudSEK accessed the BigBear admin panel and found 5,137 records across 461 organizations, including 1,032 plaintext passwords and 4,148 session cookies.

Why are stolen session cookies dangerous?

Stolen session cookies allow attackers to impersonate authenticated users, giving them access to emails, SharePoint files, and Teams chats while completely bypassing multi-factor authentication controls.

This article answers
  • bigbear phishing crew
  • bigbear 2.0 microsoft 365
  • evilginx2 phishing-as-a-service campaign
  • cloudsek bigbear investigation admin panel
  • how do attackers bypass mfa with session cookies
  • microsoft 365 credential theft campaign 2026
  • what is bigbear phishing operation
  • how does evilginx2 steal session cookies
  • microsoft 365 account hijacked via phishing
Topics
P
Patrick
Senior Technology Correspondent

Patrick covers AI infrastructure, model releases and enterprise automation. He has spent more than a decade reporting on how engineering decisions inside large platforms end up reshaping the software everyone else has to build on.

AI model launchesEnterprise automationCloud infrastructureDeveloper tooling