logo

Tycoon 2FA Phishing Kit Disrupted by Microsoft, Europol and Partners

ID: 8652cab8-452d-5884-9969-287dff490c32

STIX ID: report--8652cab8-452d-5884-9969-287dff490c32

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-03-04

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Microsoft, Europol and partner organizations coordinated a cross-border takedown of Tycoon 2FA, a prolific phishing-as-a-service platform that used adversary-in-the-middle (AiTM) techniques to bypass multifactor authentication and harvest credentials, session tokens, and real-time codes; the service sent tens of millions of phishing messages, impacted over 500,000 organizations (including healthcare and education), and used sophisticated evasion and domain-rotation techniques before seizures of infrastructure and domains disrupted its activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.