logo

Report: The Tycoon 2FA Phishing Kit Has Evolved

ID: f84c76f1-da3b-5068-abad-7d9fa0ee058a

STIX ID: report--f84c76f1-da3b-5068-abad-7d9fa0ee058a

Feed Name: KnowBe4 Blog

Threat Score
70/100

Date Published: 2026-05-22

Date Updated: 2026-05-22

Author: KnowBe4 Team

...
...

Tycoon 2FA, a phishing-as-a-service platform, has resumed operations and is actively conducting OAuth device code phishing attacks that trick users into granting OAuth tokens via Microsoft's legitimate device-login flow, enabling attackers to obtain access without exploiting technical vulnerabilities; the technique leverages social engineering to subvert MFA by changing what the MFA approval actually authorizes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.