Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Tycoon2FA Operators Resume Cloud Account Phishing Following Infrastructure

Tycoon2FA operators have resumed large-scale cloud account phishing following a recent disruption of their core infrastructure by law enforcement and industry partners. This event highlights the resilience of phishing-as-a-service (PhaaS) ecosystems and…

Tycoon2FA operators have resumed large-scale cloud account phishing following a recent disruption of their core infrastructure by law enforcement and industry partners. This event highlights the resilience of phishing-as-a-service (PhaaS) ecosystems and the limitations of infrastructure-only takedowns.

Authorities in Latvia, Lithuania, Portugal, Poland, Spain, and the UK collaborated with private-sector partners to seize 330 domains associated with Tycoon2FA's control panels and phishing pages. The platform, active since 2023, was responsible for approximately 62% of all phishing attempts blocked by Microsoft by mid-2025.

On March 4, 2026, Europol announced a coordinated technical disruption against Tycoon2FA, a subscription-based PhaaS platform that bypasses multifactor authentication (MFA) to compromise cloud email accounts. Tycoon2FA employs adversary-in-the-middle (AiTM) techniques to intercept live authentication sessions, capturing credentials and MFA tokens for Microsoft 365 and Google accounts.

CrowdStrike's Falcon Complete and Counter Adversary Operations teams reported a short-lived decline in Tycoon2FA activity following the March 4 takedown. However, within days, the volume of cloud compromises returned to early-2026 levels, with no change in the service’s tactics, techniques, and procedures (TTPs).

This event highlights the resilience of phishing-as-a-service (PhaaS) ecosystems and the limitations of infrastructure-only takedowns.
Danielle Frost · Thehackingpost

Between March 4 and March 6, at least 30 suspected Tycoon2FA-enabled phishing incidents were reported, involving multiple decoy and credential-harvesting pages. The observed TTPs remain consistent with previous activity, including phishing emails directing victims to Tycoon2FA CAPTCHA pages and the use of stolen credentials to authenticate into victims' Microsoft Entra ID environments via Romanian ISP M247 Europe SRL over IPv6.

Telemetry from Falcon Complete indicates that Tycoon2FA recovered on the same day as Europol’s announcement, with operators quickly acquiring new IPv6 addresses while continuing to use at least one address linked to pre-disruption activity. Despite the rapid resurgence, the March 4 operation is expected to have a temporary positive impact on the eCrime landscape by imposing costs on Tycoon2FA customers and affecting the service’s reputation.

Advertisement

For defenders, the Tycoon2FA case emphasizes the need for continuous visibility across identity, email, and cloud layers, real-time correlation of phishing and authentication signals, and rapid response capabilities to prevent business email compromise (BEC) and cloud account takeover before attackers can monetize access.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories