Two major phishing incidents reported in September 2026 highlight how quickly phishing attacks are evolving — and why organisations cannot rely on email security and conventional multi-factor authentication (MFA) alone.
A phishing-as-a-service operation known as BigBear 2.0 has been used to steal thousands of Microsoft 365 credentials, including authenticated session cookies that can allow attackers to bypass conventional MFA.
At the same time, customers of hardware wallet company Trezor were targeted in a large phishing campaign after attackers compromised its third-party email marketing provider, Brevo.
Although the attacks used different techniques, both demonstrate the same underlying problem: attackers continue to target people because technology alone cannot eliminate the human element of cybersecurity.
BigBear phishing operation steals thousands of Microsoft 365 credentials
Security researchers have uncovered a phishing-as-a-service operation called BigBear 2.0, which has been used to target Microsoft 365 accounts at hundreds of organisations.
According to research from CloudSEK, the operation’s infrastructure included 42 virtual private servers configured to target Microsoft 365. Researchers found evidence that the service had been used against 258 organisations, with more than 5,000 credential records exfiltrated.
The stolen data included:
- 1,032 plaintext passwords
- 4,148 session cookies
- 474 complete MFA-bypassed authentications
- Victims across more than 40 countries
- 3,331 unique victim IP addresses
The operation was still active when researchers investigated it.
How does BigBear bypass MFA?
One of the most significant aspects of the campaign is that it demonstrates why simply enabling MFA is not necessarily enough to stop modern phishing.
BigBear 2.0 uses an adversary-in-the-middle (AiTM) technique.
Rather than simply sending a victim to a fake Microsoft 365 login page, the attacker places a proxy between the victim and the legitimate Microsoft authentication service.
The victim believes they are communicating directly with Microsoft. They enter their username and password and complete their MFA challenge as normal.
However, the attacker can intercept the authentication process and capture the resulting authenticated session cookie.
That cookie can then be replayed by the attacker to gain access to the victim’s Microsoft 365 session.
The victim has successfully completed MFA, while the attacker has still obtained an authenticated session.
Why this matters for MSPs
For MSPs and MSSPs managing Microsoft 365 environments for multiple customers, attacks such as BigBear demonstrate the importance of taking a layered approach to security.
Phishing simulations can help organisations identify which employees are susceptible to credential-harvesting attacks before criminals do.
Rather than simply measuring whether an employee clicked a link, organisations can also measure whether employees report suspicious messages, which departments are most susceptible and whether repeat offenders improve over time.
Trezor customers targeted after Brevo security incident
The second major phishing incident demonstrates a different attack path.
On September 9, Trezor’s third-party email marketing provider Brevo suffered a security incident. Brevo said an attacker gained access to customer accounts and subsequently used them to send phishing emails to their contact databases.
One of the affected accounts belonged to Trezor.
The incident exposed approximately 347,000 email addresses belonging to Trezor’s opt-in newsletter database. Trezor said no Trezor systems, wallets or customer accounts were compromised.
The attackers then used the compromised email infrastructure to send a convincing phishing message appearing to come from Trezor.
The emails used the subject:
Critical Security Alert: STM32 Entropy Vulnerability
The message claimed that a vulnerability affecting Trezor hardware wallets could put users’ wallet seeds at risk.
Recipients were directed towards a malicious link and prompted to download an application that asked them to enter their wallet backup.
Trezor moved quickly to take down the malicious domain. The company said it did so within approximately 20 minutes, limiting the campaign to around 2,500 people who had clicked the link before it was disabled.
Why the Trezor attack is particularly interesting
This incident demonstrates another major challenge for modern phishing defence:
What happens when the phishing email actually comes from legitimate, trusted infrastructure?
Traditional email security systems often rely on signals such as sender reputation, domain reputation, SPF, DKIM, DMARC and known malicious infrastructure.
But if an attacker compromises a legitimate email service or customer account, some of those controls become significantly less effective.
An email can technically originate from an authorised infrastructure provider and still contain a malicious message.
Two attacks, one common target: people
The BigBear and Trezor incidents use very different techniques.
| Attack | Primary technique | Objective |
|---|---|---|
| BigBear 2.0 | Adversary-in-the-middle phishing | Steal Microsoft 365 credentials and authenticated sessions |
| Trezor | Compromised third-party email infrastructure | Deliver convincing phishing emails to a trusted customer database |
But both attacks ultimately depend on the same thing:
Convincing a person to do something they should not do.
In the BigBear campaign, the victim is encouraged to authenticate through a malicious intermediary.
In the Trezor campaign, the victim is presented with a convincing security warning appearing to originate from a company they trust.
Technology can reduce the likelihood of successful attacks, but neither email filtering nor MFA can completely eliminate the human factor.
Why regular phishing simulations matter
A phishing simulation allows organisations to safely reproduce common attack techniques without exposing employees or company data to genuine criminals.
A good phishing simulation programme should go beyond simply measuring click rates.
Organisations can track:
- Click rate — how many employees interacted with the simulated phishing link?
- Credential submission — how many attempted to enter credentials?
- Reporting rate — how many correctly reported the simulated phishing email?
- Repeat behaviour — are the same employees repeatedly falling for simulations?
- Departmental risk — are certain departments or roles consistently more susceptible?
- Trends over time — is the organisation becoming more resilient?
This provides a much more useful picture of an organisation’s human security risk.
For MSPs and MSSPs, it also creates an opportunity to provide customers with an ongoing, measurable security-awareness service rather than treating phishing training as an annual compliance exercise.
The phishing threat continues to evolve
The BigBear and Trezor incidents show that phishing is no longer simply a matter of spotting an obvious fake email.
Attackers are increasingly using:
AiTM attacks → session theft → MFA bypass
and
compromised legitimate services → trusted infrastructure → highly convincing phishing
Organisations therefore need to think beyond email filtering and basic security awareness training.
The strongest defence is layered:
Secure authentication + email security + employee training + phishing simulations + rapid reporting + continuous measurement.
For MSPs and MSSPs, this also creates an opportunity to provide customers with a measurable, recurring security-awareness service.
Want to test your organisation?
RapidPhish makes it easy to run realistic phishing simulations without the complexity of a large enterprise security-awareness platform.
Create campaigns, test employees, measure results and generate detailed reports — all from one simple platform.