logo

Tycoon2FA Phishing Service Resumes Activity Post-Takedown

ID: 38d7a547-eb82-51c8-9544-e82a57efdc7b

STIX ID: report--38d7a547-eb82-51c8-9544-e82a57efdc7b

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-03-23

Date Updated: 2026-04-22

...
...

Tycoon2FA, a subscription phishing-as-a-service that leverages adversary-in-the-middle attacks to bypass MFA, was briefly disrupted by a Europol-coordinated takedown that seized 330 domains, but activity quickly resumed; the platform has been linked to large-scale phishing (reported as ~62% of blocked attempts and ~30 million malicious emails in a month) and continues to deploy compromised domains, legitimate cloud service redirection, IPv6 automation, and AI-generated decoy pages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.