logo

Global Takedown Neutralizes Tycoon2FA Phishing Service

ID: f4264134-10c2-5c28-b27f-7c057b27d1c8

STIX ID: report--f4264134-10c2-5c28-b27f-7c057b27d1c8

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-03-04

Date Updated: 2026-04-22

...
...

Microsoft, Europol and industry partners seized infrastructure linked to Tycoon2FA, a subscription-based phishing-as-a-service that used adversary-in-the-middle techniques to intercept live authentication sessions and bypass multi-factor authentication, enabling large-scale enterprise account takeovers; investigators seized over 300 domains tied to the service, which had roughly 2,000 users and used more than 24,000 domains since August 2023, and identified likely operator aliases while urging organizations to adopt phishing-resistant auth, advanced email protections, real-time URL inspection, continuous identity risk monitoring, and training.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.