BigBear 2.0: Phishing Campaign Targeting Microsoft 365 Accounts

Posted date 17/09/2026

The campaign was discovered by CloudSEK in June 2026, although its exact start date has not been publicly established. The documented activity continued over the following months and, beginning in late July, its operators removed 26 of the 42 identified servers. In August, the phishing infrastructure stopped responding, but the administration panel remained online.

BigBear 2.0 used a proxy to intercept passwords and session cookies after victims completed multifactor authentication. CloudSEK found 5,137 records linked to 461 organizations across more than 40 countries, 258 of which experienced at least one confirmed compromise. The firm notified law enforcement and several affected organizations, but they have not publicly disclosed their response measures.

The latest confirmed status dates to September 7, 2026: the administration panel remained available, although the phishing infrastructure had been offline for nearly three weeks and only one server was listed as active. There is no public confirmation that the operation has been completely dismantled or that all compromised accounts have been recovered. No specific Microsoft statement concerning BigBear 2.0 has been identified.