logo

Europol-coordinated action disrupts Tycoon2FA phishing platform

ID: 9a48d8a0-4f88-5fdc-8ddc-4ab7e22559ce

STIX ID: report--9a48d8a0-4f88-5fdc-8ddc-4ab7e22559ce

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2026-03-04

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

The Tycoon2FA phishing-as-a-service platform, active since at least August 2023, was disrupted in a coordinated international operation led by Microsoft and Europol with multiple private partners; 330 domains belonging to the service were seized. Tycoon2FA used an adversary-in-the-middle reverse proxy to capture credentials, session cookies, and MFA codes—enabling attackers to hijack authenticated sessions and bypass MFA—while generating tens of millions of phishing emails monthly and affecting organizations worldwide, including government, education, and healthcare.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.