AI Scam SensePart of AI Sure Tech

Article

How phishing pages can copy Microsoft 365 sign-ins and bypass MFA

A reported phishing campaign aimed at Microsoft 365 users is a reminder that fake sign-in pages can look convincing. Learn the warning signs, questions to ask, and safer ways to verify unexpected login requests.

What this means

A BleepingComputer report says a phishing-as-a-service framework called BigBear 2.0 was used in a large-scale campaign tied to Microsoft 365 users. The report says attackers used fake login pages and other tricks to get people to enter credentials, and in some cases bypass multi-factor authentication.

That does not mean every Microsoft 365 alert is fake. It does mean a login page can look real enough to fool someone if they arrive there from an unexpected link, message, or prompt. Phishing often works by creating a sense of urgency and making the request feel routine.

Warning signs

Watch for these common signs of a fake or risky sign-in request:

  • A message or login page that looks like Microsoft 365, but came from an unexpected link.
  • A page asking for a password and MFA code without clearly matching the real service you meant to use.
  • A sudden login alert or repeated sign-in prompt you did not start yourself.
  • Emails or messages that push urgency, account checks, or immediate security verification.
  • Small changes in the web address, spelling, or design that make the page feel off.

Questions to ask

If you are unsure, pause and ask:

  • Did I go to this sign-in page on my own, or did a message send me here?
  • Does the web address look exactly like the service I use?
  • Why is this asking for my password and MFA code right now?
  • Was I expecting a security check or account verification request?
  • Can I confirm this another way before typing anything?

Safer next steps

If a Microsoft 365 sign-in request feels unexpected, slow down and do not rush.

  • Treat unexpected sign-in requests with caution.
  • Check whether the page address looks unfamiliar, misspelled, or only slightly different.
  • If a message asks you to confirm credentials or an MFA prompt quickly, step back and verify it through a trusted path.
  • Watch for signs of suspicious sign-in activity on your account.
  • If you already entered information, use your organization’s official support or account security process right away.

Ways to verify

Use trusted checks instead of the link in the message:

  • Open Microsoft 365 by typing the address you normally use, or by using a saved bookmark you trust.
  • Compare the login page address character by character.
  • Check for the same request inside the service itself, not just in an email or text.
  • Ask a coworker, IT team, or account admin to confirm whether the request is real.
  • Review recent sign-in activity through the official account tools if your organization provides them.

These steps do not guarantee safety, but they can help you avoid a quick mistake.

Final reminder

Phishing often relies on pressure, not just fake design. A page can look familiar and still be unsafe. When a sign-in request feels urgent or unusual, stop and verify through a trusted source before you type anything.

AI Scam Sense did not verify this event. For the original report, see: [BleepingComputer](https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/).

Browse checklists