Security1 publisher2 min readPublished
CloudSEK took administrator access to the panel and counted 5,137 stolen records coming off 42 VPS nodes into five leasing affiliates' Telegram bots, with the phishing pages dark for three weeks while the panel itself stays reachable.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
An old mechanism still works here: an Evilginx2-based proxy sits between the victim and Microsoft's real authentication endpoint under a configuration CloudSEK calls "offy," so the victim genuinely completes MFA against Microsoft while the proxy keeps the password and the session cookie that comes back [3][4]. The panel then replays that cookie through an API and holds the authenticated session [4]. The cryptography itself stays intact; the value of the completed prompt simply moves to whoever holds the cookie.
The detail that decides whether a FIDO2 rollout was worth the budget is the kit's custom JavaScript, which interferes with FIDO2/WebAuthn by disabling the browser functionality that supports it, pushing the target onto a weaker method [8]. Enrollment alone does not guarantee enforcement. If a phishable factor remains available on the account, BigBear picks it on the user's behalf, which is why CloudSEK's own guidance pairs phishing-resistant FIDO2/WebAuthn with Conditional Access that requires managed devices instead of geo-location signals [14].
Geo signals are the other thing this operation is built to defeat. The platform uses residential proxies matched to the victim's country across 69 countries so Microsoft's authentication servers do not flag the sign-in as anomalous [9]. Location-based risk scoring, in this campaign, is a check the attacker passes on purpose.
The counts come from CloudSEK's administrator access to the panel rather than from victim disclosures, in a report shared with BleepingComputer [2][15]. Read as arithmetic: 461 organizations appear in the targeting dataset and 258 had at least one completed MFA bypass, a 56 percent conversion [7][1], averaging 1.8 completed bypasses per compromised organization [2]. Session cookies outnumber plaintext passwords 4,148 to 1,032, about four to one [5][3], which tells you what the operators were actually collecting. The three categories also sum to 5,654 against a stated total of 5,137 records, an overlap of 517, so some victims are counted in more than one bucket [4].
Scope per compromised session is the whole Microsoft 365 estate: Exchange Online, Teams, SharePoint, OneDrive and Entra ID authentication, plus whatever else is reachable through single sign-on [10].
The infrastructure being down does not close the exposure. The phishing nodes have been offline for nearly three weeks, the administration panel remains online, and at least five affiliate operators received stolen credentials in real time through Telegram bots while it ran [12][6]. Data already sitting with five tenants of a leased panel stays with them regardless of any takedown. That leaves per-account work: reset exposed passwords, revoke active sessions, refresh tokens, force re-authentication on high-privileged accounts [13]. CloudSEK says it notified law enforcement and several affected organizations, which is fewer than 258 [11][7].
Ranked by verification strength, evidence, and original report placement.
A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials.
Researchers at CloudSEK gained administrator access to the BigBear control panel and found the service managed 42 VPS nodes, all configured to target Microsoft 365 in the observed operation.
The campaign uses an Evilginx2-based adversary-in-the-middle framework to intercept passwords and authenticated session cookies, allowing attackers to hijack accounts after victims complete MFA.
BigBear uses a configuration called "offy" that sets up an AiTM proxy between the victim and Microsoft's legitimate authentication infrastructure, capturing credentials including MFA and session cookies, then replaying them through an API to hijack the victim's authenticated session.
CloudSEK says the panel exfiltrated 5,137 credential records, including 474 complete MFA-bypassed authentications, 1,032 plaintext passwords and 4,148 session cookies, affecting 3,331 unique victim IPs across more than 40 countries, with the operation still active at the time of writing.
The multi-user PhaaS panel is leased to at least five affiliate operators, identified through live Telegram exfiltration bots, each receiving stolen credentials in real time.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One firm's panel counters, relayed once
The specificity is better than most phishing research because CloudSEK was inside the administration panel reading its own logs rather than counting landing pages from outside. It remains a single firm's telemetry published through a single outlet, with no Microsoft confirmation, no named victim, and a breakdown whose parts add to 5,654 against a stated total of 5,137.
Leased, staffed and geographically wide
Uptake in this story belongs to the attackers, and it is real: 42 nodes under one panel, at least five affiliates paying for seats, victims in more than 40 countries. Depth is another matter, since only 474 authentications actually completed a bypass, roughly 1.8 per compromised organization, which describes a wide net rather than sustained access.
Active, apart from the part that phishes
An operation described as still active sits awkwardly beside the same report's note that its phishing pages have been offline for close to three weeks; what stayed reachable was the panel. Choosing 258 over the 461 in the targeting data is the disciplined move in this reporting, yet "bypassed MFA at 258 organizations" still reads as live breach rather than a historical count pulled from a log.
Research that doubles as a shop window
CloudSEK sells the credential-exposure monitoring this report demonstrates, and the findings went to one outlet as an exclusive, which is the ordinary trade in vendor threat intelligence rather than a hidden agenda. The page then ends with a paid pitch for a defense-benchmarking report, so a reader's route from finding to product runs down the same screen.
Solid mechanics, soft counting
The attack chain described here behaves the way Evilginx2-class proxies are already known to behave, and the mitigations are standard practice, so that portion is safe to act on. The quantities are only as good as one panel's logging and their internal arithmetic does not close, which puts 258 and 5,137 in the range of order-of-magnitude rather than audited.
security
Vishing gets a product tier: Okta finds kits that steer the victim's browser mid-call1 publisher
security
NovaCookies: $320 a month buys a session-theft rig that rides real Docusign mail2 publishers
security
A CVSS 10.0 RCE in Entra ID was exploited in the wild, and there was nothing to patch1 publisher
build
NovaCookies turns an MFA approval into a live Microsoft 365 session for $3201 publisher
Publishers with included, body-backed reporting in this cluster.
1 article · September 7, 2026