Incident
Published 2026-09-07
Verified 2026-09-19

BigBear 2.0 Evilginx2 PhaaS: MFA bypass at 258 orgs; 5,137 credential records

CloudSEK (7 September 2026) details BigBear 2.0, an Evilginx2-based phishing-as-a-service panel targeting Microsoft 365 with an "offy" phishlet. Researchers obtained admin access to the operator panel (alias "General Boss"): 42 VPS nodes over the campaign lifecycle (many on Vultr/The Constant Company), geo-matched residential proxies, Telegram exfiltration bots for at least five affiliates, and cookie replay after victims complete MFA. Panel telemetry cited by CloudSEK: 5,137 credential records (474 complete MFA-bypassed authentications, 1,032 plaintext passwords, 4,148 session cookies) across 3,331 unique victim IPs in 40+ countries; BleepingComputer notes 258 organisations with at least one completed MFA-bypass compromise (461 in the broader targeting set). Custom JS can weaken phishing-resistant MFA (FIDO2/WebAuthn) toward weaker methods. Operation still active at publish time. Primary: CloudSEK blog; wire: BleepingComputer (7 Sep 2026).

Product
Microsoft 365 / Entra ID (targeted via AiTM phishing)
Exploited in Australia?
unknown
Patch to
Enforce phishing-resistant MFA (FIDO2/passkeys); conditional access / token protection; hunt unexpected M365 session cookies and Impossible Travel; user reporting of fake Microsoft login pages

Primary: CloudSEK — Tracking BigBear 2.0 Evilginx2 PhaaS (7 Sep 2026) · BleepingComputer (7 Sep 2026)

breaches identity cloud