Published September 15, 2026 - Washington, D.C. A phishing-as-a-service platform named BigBear compromised 258 organizations through Microsoft 365 credential phishing in early September 2026, using adversary-in-the-middle techniques to bypass multi-factor authentication and steal session tokens.
Data last verified September 15, 2026 from BleepingComputer, Microsoft Security Response Center, and CrowdStrike AitM phishing analysis.
Quick Answer
BigBear is a phishing-as-a-service platform that bypassed Microsoft 365 MFA at 258 organizations using adversary-in-the-middle techniques to steal session tokens. SMS and TOTP MFA vulnerable. Migrate to FIDO2 keys or passkeys. Last verified: Sep 15, 2026.
At a glance
- Platform: BigBear (phishing-as-a-service)
- Discovered: early September 2026
- Organizations affected: 258
- Attack vector: adversary-in-the-middle (AitM) reverse proxy
- MFA bypass: SMS, TOTP, push notification (FIDO2 immune)
- Target: Microsoft 365 credentials and sessions
- Mitigation: migrate to FIDO2 keys or passkeys
How BigBear's AitM phishing works
BigBear operates as a reverse proxy between the victim and the legitimate Microsoft 365 login page, intercepting credentials and session tokens in transit. The victim believes they are logging in directly to Microsoft.
The BigBear infrastructure consists of three components: (1) a phishing domain that mimics a Microsoft 365 login page, (2) a reverse proxy that forwards traffic to the real Microsoft login while intercepting all data, and (3) a credential and token harvesting backend. When a victim enters credentials and completes MFA on the proxy, BigBear captures the post-authentication session token. The token is then used by the attacker to access the victim's account from any device without re-authentication (BleepingComputer, September 12, 2026; CrowdStrike AitM phishing analysis, 2026).
Why SMS, TOTP, and push MFA fail against BigBear
Traditional MFA methods validate possession of a code or device, not the legitimacy of the authentication origin. AitM exploits this gap.
| MFA method | BigBear bypass? | Why | Recommendation |
|---|---|---|---|
| SMS one-time password | Vulnerable | OTP forwarded in real time by proxy | Replace with FIDO2 |
| TOTP authenticator app | Vulnerable | TOTP forwarded in real time by proxy | Replace with FIDO2 |
| Microsoft Authenticator push | Vulnerable | Push forwarded by proxy; user approves legitimate-looking request | Replace with FIDO2 or use number matching |
| FIDO2 hardware key (YubiKey) | Immune | Bound to legitimate origin via TLS | Continue |
| FIDO2 platform passkey (Windows Hello, Touch ID) | Immune | Bound to legitimate origin via TLS | Continue |
| Certificate-based authentication | Immune | Mutual TLS to legitimate domain | Continue for high-privilege accounts |
Source: FIDO Alliance, 2026; Microsoft Authenticator AitM defense, 2026; BleepingComputer, September 12, 2026.
Comparing BigBear to other PaaS platforms
BigBear is the latest in a series of phishing-as-a-service platforms discovered since 2022. Each iteration improves stealth and reliability.
| Platform | Discovered | Notable features | Affected accounts |
|---|---|---|---|
| EvilProxy | 2022 | First major AitM PaaS | Thousands |
| Caffeine | 2024 | Microsoft 365 + Google Workspace focus | 5,000+ |
| NakedPages | 2024 | Microsoft 365 session hijacking | 500+ |
| Tycoon 2FA | 2024 | Open-source, customizable | 1,000+ |
| BigBear | 2026 | Microsoft 365 focused, broad targeting | 258 (confirmed) |
Source: CrowdStrike AitM phishing analysis, 2026; BleepingComputer PaaS tracker, September 2026; Mandiant phishing service database, 2026.
Indicators of BigBear compromise
Three Microsoft 365 audit log patterns indicate possible BigBear compromise. Detection lag is typically days to weeks.
| Indicator | Log location | Detection method |
|---|---|---|
| Impossible-travel sign-ins | Microsoft Entra ID sign-in logs | Geographic anomaly detection |
| Session token reuse across multiple IPs | Microsoft 365 unified audit log | Token correlation analysis |
| New inbox rules forwarding email externally | Microsoft 365 unified audit log | Mailbox rule auditing |
| OAuth consent grants to unknown apps | Microsoft Entra ID audit logs | Consent grant monitoring |
Source: Microsoft Security Response Center AitM defense guidance, September 2026; BleepingComputer detection rules, September 2026.
Defense-in-depth strategy for organizations
Six layered controls reduce BigBear risk even if user credentials are compromised. The defense assumes some users will be phished.
| Control | Effectiveness | Implementation effort |
|---|---|---|
| Migrate to FIDO2/passkey MFA | Highest | Medium (3-6 months for large orgs) |
| Microsoft 365 Conditional Access with compliant device requirement | High | Medium |
| Browser-level phishing protection (Microsoft Edge SmartScreen, etc.) | Medium | Low |
| Disable legacy authentication protocols | Medium | Low |
| Session token revocation policies | Medium | Low |
| User phishing awareness training (Pareto) | Low for AitM | Low |
Source: Microsoft Security Response Center defense-in-depth, 2026; CrowdStrike AitM mitigation guide, 2026.
Microsoft's response and recommended migration path
Microsoft has accelerated its push toward phishing-resistant MFA and number matching in Microsoft Authenticator. The 2026 BigBear campaign is the latest evidence that SMS and TOTP are no longer adequate.
Microsoft announced in August 2026 that all Entra ID tenants will be required to use number matching for Microsoft Authenticator push notifications by year-end. Number matching requires the user to type a number from the sign-in screen into the authenticator app, preventing AitM proxies from simply forwarding the push. Microsoft also recommends deploying FIDO2 keys for all privileged accounts (Entra ID admins, Exchange admins, security admins) by Q2 2027. The combined posture of number matching plus FIDO2 keys for high-privilege accounts raises the bar significantly against BigBear-style AitM attacks (Microsoft Security Response Center, September 2026; Entra ID roadmap, August 2026).
FAQs
The questions above cover what BigBear is, how it bypasses MFA, which 258 organizations were affected, how it compares to other PaaS platforms, which MFA methods protect against AitM, and what organizations should do to defend themselves.
Written by
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practi… Read moreShow less
Fazlur Rahman is the founder of Tutorsbot, building AI-powered tools for learning and career growth. He writes about applying AI in real products and the practical side of building an ed-tech startup.









