BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. [...]
What happened
A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. [...]
Why it matters
The development may change operating conditions or market expectations around Microsoft. Further confirmation and measurable outcomes matter.
Affected entities
Microsoft · MSFTNeutral
View evidence
2 reports · 1 original report · 2 independent
- BleepingComputerPrimary source · Supports · EN · 100%BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations ↗
- The Hacker NewsIndependent · Supports · EN · 51%Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks ↗
Claims
- BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations Observed
Conflicts
No material conflict detected in the available evidence.
Timeline
- First reported
- Unverified · 64/66%
Market move following event
Market reaction is not yet available for this asset and time window.
Score explanation
Confidence · formula confidence-2.1.0
Source trust82
Independent corroboration76
Primary evidence35
Claim consistency82
Extraction confidence82
Attribution quality90
Impact · formula impact-2.1.0
Event magnitude45
Market relevance74
Entity significance94
Market breadth57
Novelty60
Urgency55
Ranking · formula rank-1.0.0
Confidence factor0.874
Freshness factor0.995
Breaking bonus0