logo

Tycoon 2FA phishing actors scatter, branch into new attacks | Threat Intelligence

ID: 08f94b40-07a3-57ce-91ca-aa20e233c726

STIX ID: report--08f94b40-07a3-57ce-91ca-aa20e233c726

Feed Name: Okta Threat Intelligence

Threat Score
78/100

Date Published: 2026-04-30

Date Updated: 2026-08-05

Author: Houssem Eddine Bordjiba, Daniel López, Jeremy Kirk

...
...

Tycoon 2FA was a widely observed phishing kit that operated as an attacker-in-the-middle proxy, relaying user credentials and capturing session tokens to replay sessions and bypass multi-factor authentication; telemetry shows thousands of phishing attempts against federated Microsoft/Okta customers in 2025–2026 with a takedown in March 2026 and subsequent detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.