THE TELL

BigBear: The Service That Walks Past Two-Factor — and Has Already Been Inside 258 Organizations

You typed your password, then the code from your app, and decided you were safe. A service called BigBear 2.0 was built for exactly that moment — to make sure it doesn't help you.

Researchers at CloudSEK got into the control panel of the BigBear 2.0 phishing service and watched it work from the inside. According to their report, shared with BleepingComputer, the service bypassed two-factor protection at at least 258 organizations and collected 5,137 records of other people's data: 1,032 plaintext passwords, 4,148 session files, and 474 completed two-factor bypasses. Victim IP addresses numbered 3,331, spread across more than forty countries.

Strip away the jargon and the mechanics are simple. A middleman sits between you and the real Microsoft sign-in page. You see the familiar form, you type your password, then the code. All of it goes on to the real Microsoft server, and the login succeeds. But the middleman keeps the pass your browser receives after sign-in: a small file that tells the server this person has already been checked. With that pass, a stranger no longer needs your code.

What it means

Two-factor protects the moment of login. It does not protect what gets handed out afterward. BigBear doesn't break the code in your app — it waits for you to type it yourself, then takes the result. That's why advice like "turn on two-factor and sleep well" is out of date. You should still turn it on. You just can't treat it as armor.

Then comes the detail that makes all of this so quiet. According to CloudSEK, the platform uses residential IP addresses matched to the victim's country, across 69 countries. To Microsoft's server, it looks like the person is signing in from their own city, on their own home internet. Separately, there's custom JavaScript that disables FIDO2/WebAuthn support in the browser — sign-in by security key or fingerprint. The most reliable login method is simply switched off, so you fall back to a password and a code.

The service isn't a lone operation. The panel is rented out: at least five operators receive stolen data in real time through Telegram bots. Breaking in has become a subscription.
Share this

One more number explains the scale in plain terms. The service ran 42 servers, and every one of them was aimed at Microsoft 365 — mail, files, work chats. Someone else's session in an account like that opens your correspondence and your documents, and through single sign-on, other company services too. One stolen pass turns into a whole keyring.

Who it matters to

People who started their first job yesterday and got a company email account. Those are exactly the inboxes that receive "confirm your sign-in" messages, and a newcomer is exactly the person who won't argue with a page that looks real. Freelancers who keep working files in a client's cloud: a stolen session means access to your messages and contracts, not an abstract "incident." And anyone used to treating the code in their app as a guarantee. It isn't one anymore, and that's worth telling everyone you ever told to turn on two-factor.

What's next

CloudSEK reported the findings to law enforcement and to some of the affected organizations. When the report was published, the admin panel was still online, while the phishing infrastructure itself had been offline for nearly three weeks. That's the thing to watch: whether it comes back on. The source names no timelines, no arrests, no further steps — what happens to the operators, nobody has said yet.

One detail to hold on to

The worst part here isn't the stolen passwords. It's the disabled FIDO2: the attackers deliberately break the most reliable sign-in method to push you back to the one they know how to get around. Which means sign-in by key or fingerprint really does get in their way. Sometimes the best security advice is visible in what the attackers work hardest to switch off.

Sources: BleepingComputer, "BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations," Bill Toulas, September 7, 2026; CloudSEK report shared with BleepingComputer.

Why we ran this7/10

Двухфакторная защита, которую всем советуют как гарантию безопасности, обходится готовым сервисом по подписке — 258 организаций и больше 5000 украденных учёток показывают, что «код из SMS» уже не спасает.

Written by THE TELL’s AI newsroom. how we work  ·  corrections

Share
← All stories← A model needed a number it couldn't find…Next: 60,000 people quietly told the NHS to stop… →
Everyone reports what happened

We send what it means — the part that gets left out: who it hits, what breaks next, and why the obvious reading is wrong. One letter, only when something actually shifts.

No spam. Leave in one click.

Prefer to follow instead? Telegram X