Tycoon 2FA phishing kit disrupted by Microsoft, Europol and partners
Microsoft and Europol say they disrupted Tycoon 2FA, a phishing-as-a-service platform that helped criminals steal credentials and bypass multifactor authentication through adversary-in-the-middle techniques. Microsoft says it used a U.S. court order to seize 330 domains that hosted Tycoon’s control panels and many of its phishing pages.
Europol says it coordinated the cross-border effort through its European Cybercrime Centre and worked with law enforcement in Latvia, Lithuania, Portugal, Poland, Spain, and the United Kingdom to seize infrastructure in their jurisdictions.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
Partners across the private sector supported the action with telemetry and infrastructure leads. Proofpoint says it provided a declaration that supported Microsoft’s civil filing and helped document Tycoon 2FA activity and infrastructure.

What Tycoon 2FA did
Tycoon 2FA sold turnkey phishing infrastructure that sat between victims and real login pages. The operator’s setup captured credentials and session tokens while the victim interacted with what looked like a normal Microsoft 365 or Gmail sign-in flow. Microsoft says the service enabled large-scale impersonation and initial access.
Europol describes Tycoon 2FA as a criminal service that enabled MFA bypass and unauthorized account access, driven by tens of millions of phishing emails per month and broad global targeting.
Key details
| Item | Details |
|---|---|
| Platform | Tycoon 2FA (phishing-as-a-service) |
| Core technique | Adversary-in-the-middle phishing to capture credentials and session tokens |
| Disruption lead | Microsoft Digital Crimes Unit |
| Domains seized | 330 domains tied to control panels and phishing pages |
| Law enforcement coordination | Europol EC3 with multiple European partners |
| Primary impact | Credential theft, session hijacking, MFA bypass |
What law enforcement and Microsoft actually seized
Microsoft says the seized domains now show a court-authorized splash page, and it framed the action as a coordinated disruption of the platform’s backbone infrastructure. Coinbase confirms the same outcome and says Microsoft seized domains that powered Tycoon’s operations, including domains that hosted control panels and certain phishing pages.
Europol emphasizes coordination and operational execution across borders, with EC3 acting as the central hub to share intelligence and translate it into action with affected countries.

Why this takedown matters
Phishing kits like Tycoon 2FA thrive because they lower the skill bar. A buyer can rent infrastructure, pick templates, and run campaigns without building proxy tooling from scratch. That model also scales quickly because operators rotate domains and host content across multiple providers.
This disruption should raise operational costs for the ecosystem, at least temporarily. It can also produce investigative value, because coordinated seizures often preserve backend data that helps investigators map affiliates, infrastructure, and payment flows. Europol explicitly points to coordinated action and intelligence sharing across jurisdictions as a core part of the operation.
What defenders should do next
- Enforce phishing-resistant MFA where possible, especially FIDO2 and passkeys for high-risk users.
- Tighten conditional access rules for session-token abuse, including device compliance, impossible travel controls, and risk-based sign-in policies.
- Monitor for reverse-proxy phishing signals such as unusual sign-in URLs, abnormal authentication redirects, and rapid token reuse.
- Block and alert on newly seen look-alike domains that mimic identity providers, even when the pages render correctly.

Practical detection notes
| Signal | Why it matters |
|---|---|
| Sudden spike in logins that complete without the usual device patterns | Session tokens often remove normal friction points |
| Multiple users clicking the same newly registered domain | PhaaS campaigns reuse infrastructure across victims |
| Conditional access “passed” but device posture looks wrong | AiTM kits can ride real sessions while the device stays unknown |
| Login page served from nonstandard hostnames | Tycoon-style kits often host convincing templates on rotating domains |
FAQ
It is a phishing-as-a-service platform that provided infrastructure to steal credentials and hijack sessions, allowing MFA bypass via adversary-in-the-middle tactics.
Microsoft says it seized 330 domains tied to Tycoon 2FA control panels and phishing pages under a U.S. court order, while Europol coordinated additional infrastructure seizures with European partners.
Disruptions can break active infrastructure and reduce volume, but operators and affiliates often rebuild. Treat this as a chance to harden identity controls and hunt for related campaign remnants.
Microsoft and Europol list broad public-private coordination. Proofpoint says it supported the civil filing with a declaration about Tycoon activity, and Coinbase says it partnered with Microsoft on the coordinated disruption.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages