{"id":421850,"date":"2026-10-03T06:48:11","date_gmt":"2026-10-03T06:48:11","guid":{"rendered":"https:\/\/malwaretips.com\/blogs\/?p=421850"},"modified":"2026-10-03T06:48:11","modified_gmt":"2026-10-03T06:48:11","slug":"bigbear-2-microsoft-365-phishing-mfa-sessions","status":"publish","type":"post","link":"https:\/\/malwaretips.com\/blogs\/bigbear-2-microsoft-365-phishing-mfa-sessions\/","title":{"rendered":"BigBear 2.0 Microsoft 365 Phishing Scam: How MFA Sessions Can Be Stolen"},"content":{"rendered":"<p>A document request arrives during the workday. Opening it appears to require the same account sign-in you complete dozens of times.<\/p><div id=\"mwtad3623782142\" class=\"gas_fallback-ad_309684--placement_406659\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3957935887\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>Nothing in that ordinary-looking moment suggests why an approved security prompt might still leave the account exposed.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1672\" height=\"941\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" alt=\"Illustrative shared-document email and work-account sign-in lure\" class=\"wp-image-421851 lazyload\" title=\"\" sizes=\"auto, (max-width: 1672px) 100vw, 1672px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/bigbear-hero.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/bigbear-hero.png 1672w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/bigbear-hero-300x169.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/bigbear-hero-1024x576.png 1024w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/bigbear-hero-1536x864.png 1536w\"><\/figure>\n<div id=\"mwtad2475659883\" class=\"gas_fallback-ad_309746-ad_309685-placement_406660\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"4456629336\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Overview<\/h2>\n<h3>The campaign behind the familiar sign-in<\/h3>\n<p>BigBear 2.0 is a phishing service built around Microsoft 365 authentication. Its operators and affiliates use deceptive links to put a relay between users and Microsoft.<\/p><div id=\"mwtad3088635723\" class=\"gas_fallback-ad_381396-ad_309685-placement_406667\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"1471373341\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p><a href=\"https:\/\/www.cloudsek.com\/blog\/tracking-bigbear-2-0-evilginx2-phishing-campaign\" target=\"_blank\" rel=\"noopener\">CloudSEK examined<\/a> an exposed campaign panel and documented its infrastructure, collected records, and methods in September 2026.<\/p>\n<p>The attacker does not need to invent a completely fake password prompt. A relay can forward the victim&#8217;s actions to the genuine service while capturing session material.<\/p>\n<p>That is why the page can feel more convincing than a crude imitation. Authentication may genuinely proceed, but through the wrong doorway.<\/p><div id=\"mwtad2098735256\" class=\"gas_fallback-ad_309686-ad_309685-placement_406668\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"6935453015\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<h3>Why MFA is not an automatic rescue here<\/h3>\n<p>Multi-factor authentication blocks many password-only attacks. BigBear&#8217;s adversary-in-the-middle approach targets the session created after a user completes that second factor.<\/p>\n<p>If the attacker captures and replays the session cookie, the account may be accessible without asking for the same code again.<\/p>\n<p>This does not make MFA useless. Phishing-resistant methods and strong device controls still matter, and not every attempted login becomes a completed compromise.<\/p><div id=\"mwtad102357622\" class=\"gas_fallback-ad_381401-ad_309685-placement_406669\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"5315249587\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>\n<p>The practical lesson is narrower: approving a routine-looking MFA prompt does not validate the website that initiated it.<\/p>\n<h3>What the observed panel measured<\/h3>\n<p>CloudSEK reported 5,137 credential records, including 1,032 plaintext passwords and 4,148 session cookies. Its panel counted 474 complete MFA-bypassed authentications.<\/p>\n<div id=\"mwtad1299994266\" class=\"gas_fallback-ad_381404-ad_309685-placement_406670\" style=\"margin-top: 50px;margin-right: 10px;margin-bottom: 50px;margin-left: 10px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8735619847\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><p>Researchers also observed 42 VPS nodes across the campaign&#8217;s lifecycle and traffic linked to 40-plus countries.<\/p>\n<p>These are campaign-panel observations, not a verified count of unique people whose mailboxes were opened or whose funds were lost.<\/p>\n<ul>\n<li>Microsoft 365 was the impersonated target, not the operator of the phishing service.<\/li>\n<li>The attack relayed real authentication and harvested session information.<\/li>\n<li>Credentials and cookies can create different kinds of follow-on risk.<\/li>\n<li>Incident response should revoke sessions as well as change passwords.<\/li>\n<\/ul>\n<div id=\"mwtad1050249844\" class=\"gas_fallback-ad_309747-ad_309685-placement_406661\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"9589536513\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>How the BigBear 2.0 Phishing Scam Works<\/h2>\n<h3>Step 1: A plausible work request introduces the link<\/h3>\n<p>Workplace accounts receive file invitations, meeting notices, and policy updates daily. A malicious email can resemble one of those normal interruptions.<\/p>\n<div id=\"mwtad950573602\" class=\"mwtadp5 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"8560433799\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>The exact pretext can vary between affiliates. A document review is an illustrative example, not a claim that every BigBear email used identical wording.<\/p>\n<p>A user may be busy enough to click without inspecting the destination. The message&#8217;s apparent usefulness does the persuasion.<\/p>\n<p>Even if a colleague&#8217;s name appears, verify an unexpected request through an established channel. Display names and email headers can mislead.<\/p>\n<div id=\"mwtad1208519008\" class=\"mwtadp6 mwtadentity-placement\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"https:\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\"\r\n     crossorigin=\"anonymous\"><\/script>\r\n<ins class=\"adsbygoogle\"\r\n     style=\"display:block; text-align:center;\"\r\n     data-ad-layout=\"in-article\"\r\n     data-ad-format=\"fluid\"\r\n     data-ad-client=\"ca-pub-7750719144850257\"\r\n     data-ad-slot=\"4034304343\"><\/ins>\r\n<script>\r\n     (adsbygoogle = window.adsbygoogle || []).push({});\r\n<\/script><\/div><p>Do not reply to the suspect message for confirmation. A compromised account or spoofed sender can answer in a reassuring tone.<\/p>\n<p>Open the shared file through your organization&#8217;s normal portal when possible. A genuine document should be discoverable there.<\/p>\n<h3>Step 2: A lookalike address stands in front of Microsoft<\/h3>\n<p>BigBear&#8217;s infrastructure used phishing domains and HTTPS. A padlock could therefore appear even when the destination was not Microsoft.<\/p>\n<p>The server acted as a relay. It showed the visitor content from the real authentication service while controlling the path between browser and service.<\/p>\n<p>That distinction matters. The page may respond correctly to an account name, password, and genuine MFA challenge.<\/p>\n<p>A convincing interaction is not the same as a trustworthy address. The browser&#8217;s actual host name remains an important clue.<\/p>\n<p>CloudSEK described multiple VPS nodes and country-matched proxy infrastructure. Those details made the operation scalable and helped avoid simple location-based warnings.<\/p>\n<p>No employee should have to inspect server infrastructure to stay safe. The actionable check is to reach Microsoft 365 through a known bookmark.<\/p>\n<h3>Step 3: The relay captures credentials on the way through<\/h3>\n<p>When a user types a password, the relay can read it and forward it to Microsoft&#8217;s real sign-in page.<\/p>\n<p>Because the legitimate service still receives the input, the victim may see the expected next step instead of an obvious error.<\/p>\n<p>A phishing page that forwards data is more dangerous than a static form. It can adapt to the authentication sequence the organization actually uses.<\/p>\n<p>CloudSEK observed plaintext passwords in the exposed panel, but not every panel record represented a captured password.<\/p>\n<p>Some sessions can be taken even when a password was not freshly typed, depending on the sign-in flow and existing account state.<\/p>\n<p>That is why responders should not dismiss an event simply because the user says, \u201cI never entered my password.\u201d<\/p>\n<h3>Step 4: A real MFA approval creates a reusable session<\/h3>\n<p>The user may receive a legitimate push notification or enter a one-time code. The relay passes that step through to Microsoft.<\/p>\n<p>After successful authentication, Microsoft issues session material to the browser. The malicious relay can capture that material as it travels back.<\/p>\n<p>An attacker can then try to replay a valid cookie. This is different from guessing a one-time code after it expires.<\/p>\n<p>CloudSEK&#8217;s panel showed 474 complete authentications that bypassed a fresh MFA challenge through this method. That is a recorded outcome in its sample.<\/p>\n<p>Phishing-resistant FIDO2 methods make these attacks harder, but the campaign reportedly attempted to steer some users toward weaker methods.<\/p>\n<p>Do not accept an unexpected request to switch authentication methods without checking with your IT team through a known channel.<\/p>\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1672\" height=\"941\" src=\"data:image\/gif;base64,R0lGODlhAQABAAAAACH5BAEKAAEALAAAAAABAAEAAAICTAEAOw==\" alt=\"Illustrative fictional work-files page showing a deceptive sign-in window\" class=\"wp-image-421852 lazyload\" title=\"\" sizes=\"auto, (max-width: 1672px) 100vw, 1672px\" data-src=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/bigbear-detail.png\" data-srcset=\"https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/bigbear-detail.png 1672w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/bigbear-detail-300x169.png 300w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/bigbear-detail-1024x576.png 1024w, https:\/\/malwaretips.com\/blogs\/wp-content\/uploads\/2026\/10\/bigbear-detail-1536x864.png 1536w\"><\/figure>\n<h3>Step 5: Affiliates receive account material quickly<\/h3>\n<p>CloudSEK found a service model with multiple affiliate operators. The panel could send collected material to Telegram channels in near real time.<\/p>\n<p>Speed matters because a stolen session may be useful before the employee notices anything wrong.<\/p>\n<p>The research described automated cookie replay. An attacker could attempt to reach email, files, or connected services while the legitimate user continued working.<\/p>\n<p>Access to a mailbox can support further impersonation. A convincing message from a real account may reach colleagues, clients, or finance staff.<\/p>\n<p>Not every collected cookie results in an opened mailbox. The campaign&#8217;s recorded totals should not be treated as confirmed downstream abuse.<\/p>\n<p>Still, a completed login through the wrong domain deserves urgent response, even if no visible damage appears yet.<\/p>\n<h3>Step 6: Account access can become another fraud attempt<\/h3>\n<p>An intruder may search mail for invoices, payroll details, or password-reset messages. They could also create forwarding rules to keep receiving new messages.<\/p>\n<p>Business email compromise often follows account access, but CloudSEK&#8217;s panel statistics alone do not prove a specific wire-transfer attempt.<\/p>\n<p>That distinction should shape both incident reports and reader advice. Investigate the account rather than assuming every possible follow-on event occurred.<\/p>\n<p>Check sent items, mailbox rules, OAuth app grants, unusual downloads, and file-sharing changes. Ask finance teams to verify any altered payment instructions.<\/p>\n<p>Notify people who received suspicious mail from the account. Their own exposure may be different from the first user&#8217;s.<\/p>\n<p>Recovery is not complete when the employee can log in again. Active sessions and persistence settings must also be addressed.<\/p>\n<div id=\"mwtad471707451\" class=\"gas_fallback-ad_309748-ad_309685-placement_406662\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3906789406\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What Makes This Different From a Simple Fake Login Page<\/h2>\n<p>Traditional phishing often collects a password and leaves the victim on a generic error screen. This relay can conduct a real login while observing it.<\/p>\n<p>The result is an unsettling combination: the password works, MFA succeeds, and the account still needs protection.<\/p>\n<p>It does not mean every Microsoft 365 login is compromised. The problem begins with a malicious link that places an outsider in the path.<\/p>\n<p>A red flag may be a domain that resembles a company name but is not part of its approved sign-in flow.<\/p>\n<p>Another is a prompt to authenticate for a document you were not expecting. Ask the sender through a separate channel before proceeding.<\/p>\n<p>Large organizations should make official sign-in routes easy to remember. A clear bookmark beats asking staff to decode dozens of similar URLs.<\/p>\n<p>Security teams should correlate the user&#8217;s report with sign-in logs, token activity, device signals, and mailbox changes. A password reset alone is insufficient.<\/p>\n<p>Phishing-resistant MFA, device-bound sessions, and conditional access can reduce exposure, but configuration and deployment vary by organization.<\/p>\n<p>Training should avoid the simplistic claim that any MFA prompt means safety. Users need to understand where they initiated the login.<\/p>\n<p>Employees should report a suspicious sign-in immediately, even if they did not see an error. Fast reporting gives defenders a chance to revoke sessions.<\/p>\n<p>Managers should avoid blaming a reporter. Shame delays notification, giving the attacker more time with a usable session.<\/p>\n<p>For small businesses without a dedicated security team, a Microsoft 365 administrator or trusted IT provider should review the account promptly.<\/p>\n<div id=\"mwtad1304768913\" class=\"gas_fallback-ad_318930-ad_309685-placement_406663\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3818335085\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What to Do if You Signed in Through a Suspicious Link<\/h2>\n<p>Tell your IT team exactly what happened, including whether you approved MFA. A successful login is relevant evidence, not reassurance.<\/p>\n<ol>\n<li><strong>Stop using the link.<\/strong> Do not return to the page to \u201ccheck\u201d it. Record the URL, email, time, and any unusual prompts you saw.<\/li>\n<li><strong>Alert your administrator immediately.<\/strong> Ask them to review the account&#8217;s sign-in activity and determine whether a session token may have been captured.<\/li>\n<li><strong>Revoke active sessions.<\/strong> Microsoft provides administrator controls for revoking sign-in sessions. This is crucial when a cookie, not just a password, is at risk.<\/li>\n<li><strong>Reset credentials through a known route.<\/strong> Change the password and review MFA methods, recovery details, and registered devices. Do not use the original link.<\/li>\n<li><strong>Inspect mailbox and app access.<\/strong> Look for forwarding rules, deleted or sent messages, new app grants, file access, and unusual downloads.<\/li>\n<li><strong>Warn affected contacts.<\/strong> If fraudulent messages left the account, notify recipients through a separate trusted channel and flag any payment instructions for verification.<\/li>\n<li><strong>Check the device when warranted.<\/strong> Malwarebytes can help inspect a device that also downloaded files; AdGuard can reduce exposure to known malicious links. Neither revokes stolen sessions.<\/li>\n<li><strong>Document and monitor.<\/strong> Preserve logs and messages, report to relevant authorities when appropriate, and monitor the account for renewed access.<\/li>\n<\/ol>\n<p>Microsoft&#8217;s incident guidance emphasizes investigation of compromised mailboxes, not merely restoring user access. Follow your organization&#8217;s response process.<\/p>\n<p>If money was transferred because of a message from the account, call the bank immediately using a verified number. Time matters for payment recalls.<\/p>\n<p>Do not send the suspicious link to colleagues as a clickable test. Share a screenshot or sanitized description with the security team instead.<\/p>\n<p>If several workers used the same lure, investigate each account separately. One person&#8217;s clean log does not clear another person&#8217;s session.<\/p>\n<div id=\"mwtad1655432010\" class=\"gas_fallback-ad_381388-ad_309685-placement_406705\" style=\"margin-top: 30px;margin-bottom: 30px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"3191649120\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>What Administrators Should Check After a Report<\/h2>\n<p>Start with the user&#8217;s account and the reported time. Compare the phishing visit with sign-in events, device details, application access, and session changes.<\/p>\n<p>Look for authentication that appears normal but begins immediately after a visit to an unfamiliar domain. A successful MFA event may still matter.<\/p>\n<p>Review conditional-access results and whether a phishing-resistant method was actually used. Do not assume the registered strongest method was used on that day.<\/p>\n<p>Examine mailbox rules, delegated access, and OAuth grants. A quiet persistence mechanism can outlast the first password change.<\/p>\n<p>Check SharePoint and OneDrive activity for unusual sharing or downloads. The account&#8217;s risk is not limited to email.<\/p>\n<p>Preserve the malicious message headers and destination URL. They can help identify other recipients and block related links across the organization.<\/p>\n<p>Contact any employee who clicked the same lure individually. Their actions and account states may differ even though the message was identical.<\/p>\n<p>If financial instructions changed, verify them by phone using an established number. Email from a compromised mailbox cannot confirm its own legitimacy.<\/p>\n<p>Record what is known and what remains uncertain. A panel&#8217;s campaign-wide record count should not be mistaken for your organization&#8217;s affected-user count.<\/p>\n<p>Microsoft&#8217;s own guidance covers session revocation and compromised-mailbox response. Use those procedures alongside local incident policy.<\/p>\n<p>After containment, fix the route that made the link credible. Better document-sharing habits and visible reporting channels can prevent the next click.<\/p>\n<p>Do not punish someone for reporting late. A culture that welcomes imperfect, early reports gives defenders a better chance to stop reuse.<\/p>\n<div id=\"mwtad2356584410\" class=\"gas_fallback-ad_381392-ad_309685-placement_406664\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>Frequently Asked Questions<\/h2>\n<h3>Is BigBear 2.0 a Microsoft product?<\/h3>\n<p>No. It is a criminal phishing service targeting Microsoft 365 users. Microsoft is the impersonated provider, not the campaign operator.<\/p>\n<p>Keep using Microsoft 365 through your organization&#8217;s verified sign-in route.<\/p>\n<h3>Can a stolen session bypass MFA?<\/h3>\n<p>It can in some circumstances. The attacker captures session material after the user completes the second factor and tries to replay it.<\/p>\n<p>MFA remains valuable, but phishing-resistant methods and session controls add stronger protection against this pattern.<\/p>\n<h3>Did 5,137 people definitely lose their accounts?<\/h3>\n<p>No. CloudSEK reported 5,137 records in the panel, including different types of captured data. Records are not identical to unique victims.<\/p>\n<p>The panel separately showed 474 complete MFA-bypassed authentications in its observed campaign.<\/p>\n<h3>Will changing the password remove a stolen cookie?<\/h3>\n<p>Do not rely on a password change alone. Ask the administrator to revoke active sessions and inspect the account for persistence.<\/p>\n<p>The exact session behavior depends on identity settings and when tokens are invalidated.<\/p>\n<h3>What if I only opened the link?<\/h3>\n<p>Opening a page is not the same as completing sign-in. Still, report the URL and any interaction to your security team.<\/p>\n<p>If you downloaded a file or granted an app permission, include that information as well.<\/p>\n<h3>How can a workplace reduce this risk?<\/h3>\n<p>Use phishing-resistant authentication where feasible, clear official bookmarks, managed browser policies, rapid reporting, and monitoring for unusual sessions.<\/p>\n<p>Review procedures for confirming document invitations and payment changes through independent channels.<\/p>\n<div id=\"mwtad576593810\" class=\"gas_fallback-ad_381392-ad_309685-placement_406665\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"2944237110\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div><h2>The Bottom Line<\/h2>\n<p>BigBear 2.0 turned an ordinary-looking Microsoft 365 login into a relay that could capture the session created after MFA.<\/p>\n<p>If you used a suspicious link, report it promptly. The fix includes session revocation and account investigation, not just a new password.<\/p>\n<div id=\"mwtad2284262218\" class=\"gas_fallback-ad_176819-ad_309685-placement_406666\" style=\"margin-top: 50px;margin-bottom: 50px;\"><script async src=\"\/\/pagead2.googlesyndication.com\/pagead\/js\/adsbygoogle.js?client=ca-pub-7750719144850257\" crossorigin=\"anonymous\"><\/script><ins class=\"adsbygoogle\" style=\"display:block;\" data-ad-client=\"ca-pub-7750719144850257\" \ndata-ad-slot=\"8386082122\" \ndata-ad-format=\"auto\" data-full-width-responsive=\"true\"><\/ins>\n<script> \n(adsbygoogle = window.adsbygoogle || []).push({}); \n<\/script>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A document request arrives during the workday. Opening it appears to require the same account sign-in you complete dozens of times. Nothing in that ordinary-looking moment suggests why an approved security prompt might still leave &#8230; <\/p>\n<p class=\"read-more-container\"><a title=\"BigBear 2.0 Microsoft 365 Phishing Scam: How MFA Sessions Can Be Stolen\" class=\"read-more button\" href=\"https:\/\/malwaretips.com\/blogs\/bigbear-2-microsoft-365-phishing-mfa-sessions\/#more-421850\" aria-label=\"Read more about BigBear 2.0 Microsoft 365 Phishing Scam: How MFA Sessions Can Be Stolen\">Read more<\/a><\/p>\n","protected":false},"author":51,"featured_media":421851,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49],"tags":[],"class_list":["post-421850","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-scam-reports","masonry-post","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-50","resize-featured-image"],"_links":{"self":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/421850","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/users\/51"}],"replies":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/comments?post=421850"}],"version-history":[{"count":1,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/421850\/revisions"}],"predecessor-version":[{"id":421853,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/posts\/421850\/revisions\/421853"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media\/421851"}],"wp:attachment":[{"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/media?parent=421850"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/categories?post=421850"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/malwaretips.com\/blogs\/wp-json\/wp\/v2\/tags?post=421850"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}