SECURITY Signal 51
CloudSEK infiltrates BigBear admin panel, uncovers 5,137 stolen Microsoft 365 records
CloudSEK researchers accessed the BigBear phishing operation's admin panel, finding 5,137 stolen Microsoft 365 records tied to 461 organizations.
The breach of BigBear's panel reveals the scale of a phishing-as-a-service operation that captures session cookies to bypass MFA, putting Microsoft 365 accounts at risk. Engineers should note that even with MFA, adversary-in-the-middle proxies can steal authenticated sessions, so phishing-resistant FIDO2/WebAuthn and conditional access policies are critical.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
The BigBear panel held 5,137 records from 461 organizations, including 1,032 plaintext passwords and 4,148 session cookies.
CloudSEK classified 474 records as complete MFA-bypassed authentications.
The operation was still active, using a residential proxy pool across 69 countries and JavaScript to disable FIDO2/WebAuthn.
THE CLUSTER