CloudSEK found 4,148 stolen session cookies and 1,032 plaintext passwords in an operation targeting 461 organizations across more than 40 countries.

A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials.

CloudSEK found 4,148 stolen session cookies and 1,032 plaintext passwords in an operation targeting 461 organizations across more than 40 countries.