Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Tycoon2FA Operators Resume Cloud Account Phishing After Infrastructure Disruption

On Tue, Mar 4, 2026, Europol, in collaboration with law enforcement agencies from six countries, conducted a coordinated operation to dismantle the Tycoon2FA platform, a phishing-as-a-service (PhaaS) operation. Despite the seizure of 330 domains crucial…

On Tue, Mar 4, 2026, Europol, in collaboration with law enforcement agencies from six countries, conducted a coordinated operation to dismantle the Tycoon2FA platform, a phishing-as-a-service (PhaaS) operation. Despite the seizure of 330 domains crucial to its infrastructure, the platform resumed its activities swiftly, reflecting its operational resilience.

Tycoon2FA was established in 2023 as a subscription service designed to circumvent multifactor authentication (MFA) protections using adversary-in-the-middle (AITM) techniques. The platform intercepts live authentication sessions, posing a significant threat to cloud account security. By mid-2025, Tycoon2FA was responsible for 62% of blocked phishing attempts reported by Microsoft, with over 30 million malicious emails sent monthly.

The disruption on Mar 4, 2026, led to a temporary reduction in Tycoon2FA activities, with a notable decline in phishing attempts to 25% of pre-disruption levels. However, the platform quickly recovered, restoring its operations to previous levels within days, indicating the resilience of its core service.

Despite the seizure of 330 domains crucial to its infrastructure, the platform resumed its activities swiftly, reflecting its operational resilience.
Megan Forbes · Thehackingpost

Post-disruption, Tycoon2FA's tactics remained consistent. Phishing emails redirected victims to counterfeit CAPTCHA pages, where session cookies and credentials were captured. The platform used these details to gain unauthorized access to Microsoft 365 accounts. New infrastructure, including IPv6 addresses from M247 Europe SRL, was quickly deployed, maintaining the platform's operational continuity.

Organizations, especially those using Microsoft 365 or Google cloud services, should not rely solely on MFA as a defense mechanism. It is critical to implement conditional access policies, monitor DNS resolutions, and scrutinize cloud authentication logs for early detection of phishing activities. Regular employee training on identifying phishing attempts is also essential.

Advertisement

For more detailed information, refer to the detailed report .

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories