Phishing Operation Bypasses MFA at 258 Organizations
Cybersecurity researchers at CloudSEK have uncovered a phishing-as-a-service operation called BigBear 2.0 that bypassed multifactor authentication (MFA) at 258 organizations worldwide.
The operation, which was discovered in June 2026, used an adversary-in-the-middle framework called Evilginx2 to capture authenticated session cookies issued by Microsoft and replay them to gain unauthorized access.
The phishing proxy also utilized residential proxies in 69 countries to make suspicious logins appear more normal and weaken location-based security controls.
CloudSEK identified at least five affiliate operators receiving stolen information through separate Telegram bots, suggesting that the operation is designed for multiple customers rather than a single attacker.