{
  "id": 6283040,
  "title": "BigBear phishing crew nets thousands of Microsoft 365 credentials",
  "url": "https://urgent.news/2026/09/08/bigbear-phishing-crew-nets-thousands-of-microsoft-365-credentials",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-08T13:26:00.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/security/2026/09/08/bigbear-phishing-crew-nets-thousands-of-microsoft-365-credentials/5294944"
  },
  "original_language": "en",
  "account": "A Microsoft 365 phishing operation, known as BigBear 2.0, has stolen thousands of credentials belonging to hundreds of organizations. Researchers from CloudSEK accessed the crooks' admin panel, which contained 5,137 records associated with 461 organizations. Among these records, 1,032 were plaintext passwords and 4,148 session cookies. The researchers classified 474 records as complete MFA-bypassed authentications, indicating that attackers had managed to capture authenticated Microsoft 365 sessions. This could potentially give the attackers more than just an inbox, as a hijacked Microsoft 365 account can provide access to email, calendars, Teams conversations, and files stored in SharePoint and OneDrive. In the worst-case scenario, this could lead to business email compromise, internal phishing, data theft, and lateral movement. The BigBear operation is still active, with its default phishing template, \"offy,\" specifically designed to intercept Microsoft 365 authentication. The phishing infrastructure operates as an adversary-in-the-middle proxy between the victim and Microsoft's real login service, allowing attackers to bypass MFA and potentially access Microsoft 365 services without the victim's knowledge.",
  "summary": "Researchers got inside the crooks' admin panel and found 5,137 stolen records tied to 461 organizations",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}