logo

Europol, Microsoft, TrendAI™ and Collaborators Halt Tycoon 2FA Operations

ID: 99ca6a70-8603-5e7e-9e66-a8302278b073

STIX ID: report--99ca6a70-8603-5e7e-9e66-a8302278b073

Feed Name: TrendAI Security Blog

Threat Score
75/100

Date Published: 2026-01-01

Date Updated: 2026-08-11

...
...

A multinational coalition led by Microsoft and Europol, supported by TrendAI™ and other private partners, disrupted Tycoon 2FA — a large-scale phishing-as-a-service platform that used AitM proxies to capture credentials, MFA codes, and session cookies enabling account takeovers. TrendAI™ attributed the service to an operator using the monikers “SaaadFridi”/“Mr_Xaad”, reported the platform had roughly 2,000 criminal customers and used over 24,000 domains, and warned that harvested credentials and cookies fuel a broader cybercrime ecosystem with follow-on impacts like BEC, data theft, and ransomware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.