Tycoon2FA Operators Resume Cloud Account Phishing Following Infrastructure
Tycoon2FA operators have resumed large-scale cloud account phishing following a recent disruption of their core infrastructure by law enforcement and industry partners. This event highlights the resilience of phishing-as-a-service (PhaaS) ecosystems and…
Tycoon2FA operators have resumed large-scale cloud account phishing following a recent disruption of their core infrastructure by law enforcement and industry partners. This event highlights the resilience of phishing-as-a-service (PhaaS) ecosystems and the limitations of infrastructure-only takedowns.
Authorities in Latvia, Lithuania, Portugal, Poland, Spain, and the UK collaborated with private-sector partners to seize 330 domains associated with Tycoon2FA's control panels and phishing pages. The platform, active since 2023, was responsible for approximately 62% of all phishing attempts blocked by Microsoft by mid-2025.
On March 4, 2026, Europol announced a coordinated technical disruption against Tycoon2FA, a subscription-based PhaaS platform that bypasses multifactor authentication (MFA) to compromise cloud email accounts. Tycoon2FA employs adversary-in-the-middle (AiTM) techniques to intercept live authentication sessions, capturing credentials and MFA tokens for Microsoft 365 and Google accounts.
CrowdStrike's Falcon Complete and Counter Adversary Operations teams reported a short-lived decline in Tycoon2FA activity following the March 4 takedown. However, within days, the volume of cloud compromises returned to early-2026 levels, with no change in the service’s tactics, techniques, and procedures (TTPs).
This event highlights the resilience of phishing-as-a-service (PhaaS) ecosystems and the limitations of infrastructure-only takedowns.
Between March 4 and March 6, at least 30 suspected Tycoon2FA-enabled phishing incidents were reported, involving multiple decoy and credential-harvesting pages. The observed TTPs remain consistent with previous activity, including phishing emails directing victims to Tycoon2FA CAPTCHA pages and the use of stolen credentials to authenticate into victims' Microsoft Entra ID environments via Romanian ISP M247 Europe SRL over IPv6.
Telemetry from Falcon Complete indicates that Tycoon2FA recovered on the same day as Europol’s announcement, with operators quickly acquiring new IPv6 addresses while continuing to use at least one address linked to pre-disruption activity. Despite the rapid resurgence, the March 4 operation is expected to have a temporary positive impact on the eCrime landscape by imposing costs on Tycoon2FA customers and affecting the service’s reputation.
For defenders, the Tycoon2FA case emphasizes the need for continuous visibility across identity, email, and cloud layers, real-time correlation of phishing and authentication signals, and rapid response capabilities to prevent business email compromise (BEC) and cloud account takeover before attackers can monetize access.
Based on reporting by GBHackers.
