Most small business owners assume that enabling multi-factor authentication on Microsoft 365 means their accounts are safe. A phishing service known as BigBear proved that assumption dangerously wrong. Across 258 organisations, attackers used BigBear to intercept live login sessions and bypass MFA entirely — not by cracking it, but by working around it in real time. If your business runs on Microsoft 365, this incident is worth understanding.
How MFA Bypass Phishing Actually Works
Traditional phishing steals your password. MFA bypass phishing goes further. Services like BigBear act as a silent middleman between the victim and the real Microsoft login page. When an employee clicks a malicious link and types in their credentials, the phishing kit forwards those credentials to Microsoft on their behalf — instantly. Microsoft sends the MFA code to the employee's phone, the employee enters it on what looks like a legitimate page, and that code is relayed to the attacker in real time. The attacker now has a fully authenticated session cookie, which gives them access to the account without ever needing the password or the MFA code again.
This technique is called adversary-in-the-middle, or AiTM phishing. It is not new in concept, but the industrialisation of it through services like BigBear — sold to criminals as a ready-to-use tool — means the barrier to launching this kind of attack has collapsed. You no longer need to be a sophisticated hacker. You need a subscription and a target list.
Why Small and Medium Businesses Are Particularly Exposed
Large enterprises often deploy advanced email filtering, conditional access policies, and security teams that monitor for anomalous logins in real time. Most SMBs do not have those layers. They rely on Microsoft 365's default settings, a password policy, and MFA — all of which BigBear-style attacks are specifically designed to defeat.
The 258 organisations confirmed in this campaign are almost certainly an undercount. These are the ones identified through investigation. Many more may have been compromised without realising it, because a stolen session cookie does not trigger a password reset alert. The attacker logs in quietly, reads emails, accesses SharePoint files, sets up mail forwarding rules, and in some cases uses the trusted account to launch further phishing attacks against the victim's own clients and suppliers.
For an SMB, the downstream damage — lost contracts, regulatory exposure, customer notification obligations — can be severe and long-lasting.
What You Should Check and Change Right Now
The first priority is reviewing your Microsoft 365 conditional access settings. Standard MFA is no longer sufficient protection against AiTM attacks. Microsoft offers phishing-resistant authentication methods, including passkeys and certificate-based authentication, that do not rely on one-time codes that can be intercepted. If your IT provider has not mentioned these options, it is time to ask.
Second, audit your active mail forwarding rules. Attackers who gain access via session hijacking frequently set up silent forwarding rules to exfiltrate email over time. These rules often survive password changes because they are applied at the account level, not tied to the session that created them.
Third, consider what else sits alongside your Microsoft 365 environment. Credentials from a compromised 365 account are often reused elsewhere, or the account itself connects to financial platforms, CRMs, and cloud storage. A breach in one place rarely stays contained to that one place.
Finally, assume that some version of your company's credentials is already circulating somewhere you cannot see. Infostealer malware, previous data breaches, and dark web markets regularly surface business email addresses paired with passwords — sometimes before an active attack has even begun.
MFA Bypass Phishing Is a Signal, Not an Anomaly
BigBear is not an outlier. It is evidence of a broader shift: the tools for bypassing standard security controls are now widely available, cheap, and easy to operate. The organisations that weather this environment are not necessarily the ones with the biggest budgets. They are the ones that maintain visibility — knowing what credentials are exposed, what domains are being spoofed, and what their attack surface looks like from the outside.
Breachrr monitors breach databases, infostealer dumps, dark web markets, public code repositories, and domain infrastructure specifically for SMBs who do not have a security team watching these channels full time. If you want to know what attackers can already see about your business, run a free audit at breachrr.com/audit.
Want to see if your company is exposed?