BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
黑客利用名为 BigBear 2.0 的钓鱼即服务框架,成功绕过 258 家组织的多因素认证(MFA),窃取超过 5,000 个 Microsoft 365 凭证。该攻击通过钓鱼服务自动化执行,导致大量企业账户信息泄露,引发严重的安全风险。
EVENT DOSSIER
On September 7, 2026, the cybersecurity site Bleeping Computer reported that hackers used the BigBear 2.0 phishing service framework to successfully bypass multi-factor authentication (MFA) for 258 organizations and steal over 5,000 Microsoft 365 credentials. The attack was carried out automatically through phishing services, resulting in the leakage of a large amount of corporate account information and causing serious security risks.
黑客利用名为 BigBear 2.0 的钓鱼即服务框架,成功绕过 258 家组织的多因素认证(MFA),窃取超过 5,000 个 Microsoft 365 凭证。该攻击通过钓鱼服务自动化执行,导致大量企业账户信息泄露,引发严重的安全风险。