Updated
Updated · Computerworld · Sep 8
CloudSEK Uncovers 5,137-Record BigBear 2.0 MFA-Bypass Phishing Operation
Updated
Updated · Computerworld · Sep 8

CloudSEK Uncovers 5,137-Record BigBear 2.0 MFA-Bypass Phishing Operation

3 articles · Updated · Computerworld · Sep 8

Summary

  • CloudSEK said BigBear 2.0’s admin panel held 5,137 credential records tied to 461 organizations in more than 40 countries, including 4,148 captured session cookies and 1,032 plaintext passwords.
  • At least 474 records showed completed Microsoft 365 logins where attackers stole authenticated session cookies after users passed MFA, letting them reuse the session without another challenge.
  • The service runs on Evilginx2 and uses country-matched residential proxies plus code that disables FIDO2/WebAuthn on phishing pages, weakening location checks and steering victims toward phishable methods.
  • IT services and managed service providers made up 151 of the targeted organizations, a high-value sector because staff often hold privileged access to customer environments and admin systems.
  • Researchers said BigBear 2.0 turns session hijacking into a scalable phishing-as-a-service model, pushing defenders to treat cookies and tokens as high-value credentials and revoke sessions—not just reset passwords—after compromise.

Insights

When attackers can manipulate code to disable your strongest security keys, is any cloud-based authentication truly safe from interception?
How are cybercriminals hijacking corporate networks through managed service providers without ever triggering a single traditional security alert?