TL;DR
Microsoft 365 phishing can steal a signed-in session even after an employee completes ordinary multifactor authentication. The BigBear 2.0 investigation illustrates why businesses should require phishing-resistant authentication for sensitive access, review weaker fallback options, and prepare to investigate account compromise. MFA remains essential, but the method and the policies behind it matter.
Your employee enters a password, approves the authentication request, and gets back to work. Everything appears normal. Could an attacker still gain access?
With some Microsoft 365 phishing attacks, yes. A successful MFA prompt does not prove that the website guiding the employee through sign-in is trustworthy.
For a business owner, the useful question is more specific than “Do we have MFA?” Ask which authentication methods your business requires and whether employees can fall back to something weaker.
What did researchers find in BigBear 2.0?
In a September 7, 2026 report, CloudSEK described BigBear 2.0, a phishing service targeting Microsoft 365. Researchers reported discovering it in June 2026. The service intercepts authentication through an attacker-controlled website. This is account phishing, not evidence that Microsoft’s own infrastructure was breached.
Did You Know?
CloudSEK reported 4,148 captured session cookies and 474 completed MFA-bypass authentications. These are different measurements, not a count of unique compromised businesses or people. Source: CloudSEK’s BigBear 2.0 investigation.
How can Microsoft 365 phishing get past MFA?
An adversary-in-the-middle attack places a malicious website between the employee and the legitimate sign-in service. It relays the login process while capturing information passing through it.
After the employee completes a phishable MFA method, the attacker can capture the session cookie. This cookie acts as the browser’s proof of authentication. Reusing it can let the attacker access the session without repeating the MFA challenge. CloudSEK explains this process in its technical report.
For employees, the practical lesson is to treat the route to the sign-in page as part of the security decision. Use a saved bookmark or your normal Microsoft 365 application when an unexpected document request asks you to sign in. Our guide to lookalike domains explains how deceptive addresses can appear familiar.
Does this mean MFA is no longer useful?
No. MFA adds a requirement beyond knowing a password. Removing it would remove that protection. The better response is to review whether the methods allowed for important accounts match the threats those accounts face.
Microsoft distinguishes ordinary MFA, passwordless MFA, and phishing-resistant MFA. Those labels are not interchangeable. For example, its authentication-strength documentation does not classify Microsoft Authenticator phone sign-in as phishing-resistant. Source: Microsoft’s authentication-strength overview.
For a broader comparison, read MFA Options for Small Businesses: Which Method Should You Use?
What should businesses require instead?
Phishing-resistant authentication is designed to resist fraudulent sign-in sites. Microsoft’s supported options include FIDO2 security keys and Windows Hello for Business. Conditional Access authentication strengths let administrators require an appropriate method before granting access to a protected resource. Microsoft documents the supported methods and requirements here.
Enrollment is different from enforcement
Handing an employee a security key does not establish that every relevant sign-in must use it. The business needs to verify which policies apply, which applications they cover, and what alternatives still satisfy those policies.
CloudSEK reported that BigBear interfered with WebAuthn to steer victims toward weaker authentication. That is a downgrade attempt, not evidence that attackers broke FIDO2 cryptography. Source: CloudSEK.
PCC’s Conditional Access guide explains how access policies fit into Microsoft 365 security.
What could this mean for a small business?
Consider a hypothetical San Rafael construction company. Its office manager receives an unexpected subcontractor document request during a busy morning. A convincing sign-in page and a familiar MFA prompt make the request feel routine.
If an attacker gains access to that mailbox, the business may face more than an email problem. Conversations about invoices, project changes, and customer relationships can become useful material for impersonation. Microsoft identifies compromised mailboxes as a route for sending malicious messages both inside and outside an organization. Source: Microsoft’s compromised-account guidance.
Our recommendation is to keep payment verification independent of email. If payment instructions change, call the vendor using a previously verified number. A familiar email address should not be the only reason a payment is approved.
Use What Is Phishing? A Simple Guide for Employees as a starting point for staff education.
What should you ask your IT provider to review?
Ask for a short written review with five concrete answers:
- Coverage: Which accounts and applications require phishing-resistant authentication today?
- Alternatives: Can those users satisfy access requirements with a weaker method?
- Exceptions: Who is excluded, why, and when will each exception be reviewed?
- Recovery: How is identity verified when someone loses a key or replaces a phone?
- Response: Who investigates suspicious account activity, including outside normal business hours?
PCC recommends prioritizing administrators, finance staff, owners, and people with broad access to sensitive client information. Then expand through a planned rollout. The review should produce named owners and next steps, not just a statement that MFA is enabled.
Test before enforcing new requirements
Microsoft recommends requiring phishing-resistant MFA for administrative roles. Its deployment guidance also warns about lockouts, calls for registering suitable methods first, and starts policies in report-only mode before enforcement. Source: Microsoft’s administrator protection guidance.
Before expanding a policy, test everyday work, recovery, and emergency access. Confirm licensing and compatibility. A control that employees cannot use safely will generate pressure for exceptions.
What if someone already signed in through a suspicious link?
Contact your IT support team immediately using a known phone number or established support channel. Tell them whether you entered a password, completed MFA, or downloaded anything. Preserve the suspicious message for investigation.
A password change alone is not a complete response plan. Microsoft’s guidance includes disabling the affected account during investigation, revoking sessions, and reviewing settings that could preserve unauthorized access. The team should examine authentication methods, mailbox rules, forwarding, and application permissions as appropriate. See Microsoft’s account-compromise response guidance.
Businesses should know in advance how to reach their cybersecurity support provider and who can authorize urgent containment.
Frequently Asked Questions
Can Microsoft 365 phishing bypass MFA?
Some attacks can capture an authenticated session after a user completes a phishable MFA method. This does not mean every MFA method offers the same protection.
Is Microsoft Authenticator phishing-resistant?
The app name alone does not establish phishing resistance. Push approvals and one-time codes should not be treated as equivalent to a properly configured phishing-resistant credential. Ask which method is actually being used and required.
Did BigBear 2.0 break FIDO2 security keys?
The report describes attempts to steer users toward weaker alternatives. It does not demonstrate a cryptographic defeat of FIDO2 security keys.
Should we turn off MFA while changing methods?
No. Keep existing protection in place while your IT provider plans enrollment, tests stronger requirements, and manages the transition.
Where should a small business start?
Request a review of administrator and other high-impact accounts, their required authentication methods, policy exceptions, and recovery procedures. Assign an owner and completion date to each needed change.
About Professional Computer Concepts
Professional Computer Concepts (PCC) is a trusted Managed IT and Cybersecurity provider serving the Bay Area for over 20 years. We help small and midsize businesses simplify their IT, strengthen security, and modernize operations. Explore our services:
Managed IT Services | Cybersecurity | Cloud Solutions
From PCC’s Desk
Employees reasonably expect that following the sign-in instructions will protect them. The business has a responsibility to make those instructions and the controls behind them dependable. Reviewing the authentication methods you require is a practical place to start.
If you want help understanding your Microsoft 365 authentication settings and identifying the next sensible improvement, let’s talk.
