logo

Tycoon 2FA Goes Boom as Europol, Vendors Bust Phishing Platform

ID: c517a3c3-9bb0-588d-8370-72837d59b8a4

STIX ID: report--c517a3c3-9bb0-588d-8370-72837d59b8a4

Feed Name: Proofpoint Blog

Threat Score
80/100

Date Published: 2026-03-05

Date Updated: 2026-04-28

...
...

Europol, Microsoft and multiple private-sector partners disrupted Tycoon 2FA, a prominent phishing‑as‑a‑service that used adversary‑in‑the‑middle proxying to capture live session tokens and bypass multifactor authentication, impacting an estimated 96,000 victims and accounting for roughly 62% of Microsoft-blocked phishing attempts; the operation seized 330 domains and infrastructure across several countries while partners urged adoption of phishing-resistant MFA (e.g., FIDO2/passkeys) and warned that operators may attempt to rebuild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.