Tycoon2FA Operators Resume Cloud Account Phishing After Infrastructure Disruption
On Tue, Mar 4, 2026, Europol, in collaboration with law enforcement agencies from six countries, conducted a coordinated operation to dismantle the Tycoon2FA platform, a phishing-as-a-service (PhaaS) operation. Despite the seizure of 330 domains crucial…
On Tue, Mar 4, 2026, Europol, in collaboration with law enforcement agencies from six countries, conducted a coordinated operation to dismantle the Tycoon2FA platform, a phishing-as-a-service (PhaaS) operation. Despite the seizure of 330 domains crucial to its infrastructure, the platform resumed its activities swiftly, reflecting its operational resilience.
Tycoon2FA was established in 2023 as a subscription service designed to circumvent multifactor authentication (MFA) protections using adversary-in-the-middle (AITM) techniques. The platform intercepts live authentication sessions, posing a significant threat to cloud account security. By mid-2025, Tycoon2FA was responsible for 62% of blocked phishing attempts reported by Microsoft, with over 30 million malicious emails sent monthly.
The disruption on Mar 4, 2026, led to a temporary reduction in Tycoon2FA activities, with a notable decline in phishing attempts to 25% of pre-disruption levels. However, the platform quickly recovered, restoring its operations to previous levels within days, indicating the resilience of its core service.
Despite the seizure of 330 domains crucial to its infrastructure, the platform resumed its activities swiftly, reflecting its operational resilience.
Post-disruption, Tycoon2FA's tactics remained consistent. Phishing emails redirected victims to counterfeit CAPTCHA pages, where session cookies and credentials were captured. The platform used these details to gain unauthorized access to Microsoft 365 accounts. New infrastructure, including IPv6 addresses from M247 Europe SRL, was quickly deployed, maintaining the platform's operational continuity.
Organizations, especially those using Microsoft 365 or Google cloud services, should not rely solely on MFA as a defense mechanism. It is critical to implement conditional access policies, monitor DNS resolutions, and scrutinize cloud authentication logs for early detection of phishing activities. Regular employee training on identifying phishing attempts is also essential.
For more detailed information, refer to the detailed report .
Based on reporting by Cyber Security News.
