Urgent.News

What's breaking now, across thousands of outlets.

Tech

BigBear phishing crew nets thousands of Microsoft 365 credentials

Researchers got inside the crooks' admin panel and found 5,137 stolen records tied to 461 organizations

BigBear phishing crew nets thousands of Microsoft 365 credentials

A Microsoft 365 phishing operation, known as BigBear 2.0, has stolen thousands of credentials belonging to hundreds of organizations. Researchers from CloudSEK accessed the crooks' admin panel, which contained 5,137 records associated with 461 organizations. Among these records, 1,032 were plaintext passwords and 4,148 session cookies.

The researchers classified 474 records as complete MFA-bypassed authentications, indicating that attackers had managed to capture authenticated Microsoft 365 sessions. This could potentially give the attackers more than just an inbox, as a hijacked Microsoft 365 account can provide access to email, calendars, Teams conversations, and files stored in SharePoint and OneDrive.

In the worst-case scenario, this could lead to business email compromise, internal phishing, data theft, and lateral movement. The BigBear operation is still active, with its default phishing template, "offy," specifically designed to intercept Microsoft 365 authentication. The phishing infrastructure operates as an adversary-in-the-middle proxy between the victim and Microsoft's real login service, allowing attackers to bypass MFA and potentially access Microsoft 365 services without the victim's knowledge.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at theregister.com →

More in Tech

More from Tuesday 8 September →