logo

Authorities Shut Down Tycoon 2FA Phishing Platform Used to Bypass MFA

ID: 6202955c-c8c0-55d3-b5cc-fa81dbb10d49

STIX ID: report--6202955c-c8c0-55d3-b5cc-fa81dbb10d49

Feed Name: HackRead

Threat Score
80/100

Date Published: 2026-03-05

Date Updated: 2026-04-22

Author: Waqas

...
...

Europol and international partners dismantled Tycoon 2FA, a commercial reverse‑proxy phishing‑as‑a‑service that bypassed multi‑factor authentication by capturing session tokens, enabling widespread credential theft and account takeover. The service operated as a subscription offering phishing templates and dashboards, was linked to tens of millions of phishing emails monthly and attacks on over 500,000 organizations, and investigators seized roughly 330 domains and disabled hosting resources—though researchers warn similar frameworks will likely reappear.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.