BigBear 2.0 disables hardware security keys to steal Microsoft 365 cookies
BigBear 2.0 is a phishing-as-a-service platform that deliberately disables hardware security key (FIDO2) authentication in victims’ browsers by injecting custom JavaScript, then steals Microsoft 365 session cookies. The approach compromised 258 organizations across more than 40 countries, capturing 5,137 credential records, according to a CloudSEK TRIAD report.