logo

Act Now: Phishing-as-a-Service Attacks are on the Rise

ID: a4f3d321-f791-503a-a8af-a8e24a9b3796

STIX ID: report--a4f3d321-f791-503a-a8af-a8e24a9b3796

Feed Name: KnowBe4 Blog

Threat Score
70/100

Date Published: 2025-03-24

Date Updated: 2026-04-28

Author: Stu Sjouwerman

...
...

Phishing-as-a-service (PhaaS) platforms generated more than one million phishing attacks in January–February 2025, according to Barracuda. Three platforms—Tycoon 2FA (dominant, ~89% of observed incidents), EvilProxy (~8%), and the new Sneaky 2FA (~3%)—accounted for nearly all activity. Sneaky 2FA specifically targets Microsoft 365, pre-fills spoofed login pages by abusing Microsoft’s "autograb" feature, and can bypass multi-factor authentication using a Telegram-based bot workflow. Barracuda recommends security awareness training, reporting suspicious login pages, performing in-depth log analysis, and checking for MFA anomalies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.