Find notable cyber news and cases, enriched with sources, timelines, and signals.

BigBear 2.0 Microsoft 365 phishing campaign

Campaign
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

The BigBear 2.0 phishing campaign is bypassing MFA to steal Microsoft 365 credentials from 258 organizations, putting account sessions and cloud data at risk. The operation uses an Evilginx2-based AiTM flow to intercept passwords and authenticated session cookies after victims complete login. It has already produced more than 5,000 credential records and affected 3,331 unique victim IPs across 40+ countries.

Related Happenings

UNC7005 (Storm-2945) targeted OAuth and WhatsApp phishing campaign

Campaign
H score16 First: 20.08.2026 22:59 Last: 20.08.2026 22:59 Sources 1

About this happening: A UNC7005 (Storm-2945) campaign is hijacking accounts with OAuth, WhatsApp linking, and device-code phishing across academia, diplomatic, nonprofit, and Euro...

Greatness PhaaS expands into device code phishing and integrated token-theft operations

Threat Actor Meta
H score40 First: 04.08.2026 20:27 Last: 04.08.2026 20:27 Sources 1

About this happening: Greatness PhaaS has added device code phishing, expanding its crimeware panel into a broader token-theft ecosystem that makes MFA bypass easier for customers targe...

LogoKit real-time per-victim phishing campaign

Campaign
H score35 First: 29.07.2026 19:00 Last: 29.07.2026 19:00 Sources 1

About this happening: The LogoKit phishing-as-a-service campaign now builds a unique login page per victim in real time, making credential theft harder to detect and block. It uses live scree...

Kratos ecosystem shift changes threat-actor operations

Threat Actor Meta
H score39 First: 22.07.2026 02:07 Last: 22.07.2026 02:07 Sources 1

About this happening: The Kratos phishing-as-a-service ecosystem was dismantled after it scaled to more than 1,800 criminal customers, exposing a subscription model that drove roughly 15,000...

Forg365 PhaaS industrializes Microsoft 365 credential theft and session hijacking

Threat Actor Meta
H score36 First: 13.07.2026 16:03 Last: 13.07.2026 16:03 Sources 1

About this happening: Forg365 has emerged as a subscription-based phishing platform that lowers the barrier to Microsoft 365 account theft while scaling session hijacking and mailbox ab...

Timeline

  1. 07.09.2026 18:39 2 articles · 1h ago

    BigBear 2.0 bypasses MFA at 258 organizations

    Initial Disclosure

    Researchers at CloudSEK identified BigBear 2.0 as a phishing-as-a-service operation using an Evilginx2-based adversary-in-the-middle flow to intercept passwords and authenticated session cookies after victims completed multi-factor authentication. The service was configured around 42 VPS nodes targeting Microsoft 365, used custom JavaScript to interfere with FIDO2/WebAuthn, and relied on geo-matched residential proxies to reduce authentication alerts. CloudSEK assessed that the panel had exfiltrated 5,137 credential records, including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords, and 4,148 session cookies, affecting 258 distinct organizations and 3,331 unique victim IPs across 40+ countries while the operation remained active.

    Show sources