Tycoon 2FA phishing actors scatter, branch into new attacks | Threat Intelligence
ID: 08f94b40-07a3-57ce-91ca-aa20e233c726
STIX ID: report--08f94b40-07a3-57ce-91ca-aa20e233c726
Feed Name: Okta Threat Intelligence
Date Published: 2026-04-30
Date Updated: 2026-08-05
Author: Houssem Eddine Bordjiba, Daniel López, Jeremy Kirk
Tycoon 2FA was a widely observed phishing kit that operated as an attacker-in-the-middle proxy, relaying user credentials and capturing session tokens to replay sessions and bypass multi-factor authentication; telemetry shows thousands of phishing attempts against federated Microsoft/Okta customers in 2025–2026 with a takedown in March 2026 and subsequent detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
