// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-wedgDTG 0600Z
ColdRecon / Breach Radar / Microsoft
Breach Record

Microsoft

DISCLOSED 2026-09-08 · PHISHING

The BigBear 2.0 phishing-as-a-service platform compromised 258 Microsoft 365 organizations across 40+ countries by using custom JavaScript to disable FIDO2 hardware key authentication before stealing authenticated session cookies. This highlights that organizations deploying FIDO2 with weaker fallback methods remain vulnerable to session hijacking.

The record

What we know

Disclosed
2026-09-08
Attack vector
Phishing
Sources

Cited reporting

Similar vector · recent

Other phishing breaches on file

This page is the permanent ColdRecon entry for the Microsoft disclosure. It updates if new public reporting emerges. All tracked breaches →

Microsoft just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →