Tycoon 2FA phishing actors disperse, branch into new attacks | Threat Intelligence
ID: 273e86a2-f71c-523e-90a2-46dd7d8a57f1
STIX ID: report--273e86a2-f71c-523e-90a2-46dd7d8a57f1
Feed Name: Threat Intelligence | Blog | Okta
Threat Score
Date Published: 2026-05-02
Date Updated: 2026-07-16
Author: Houssem Eddine Bordjiba, Daniel López, Jeremy Kirk
...
...
Tycoon 2FA is a widely observed phishing kit that operated as a transparent reverse proxy to capture session tokens and relay MFA challenges, allowing attackers to replay tokens and bypass both login and MFA for account takeover; Okta telemetry shows thousands of attempted phishes at peak and continued detections after a takedown.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
