Tycoon 2FA phishing kit disrupted by Microsoft, Europol and partners


Microsoft and Europol say they disrupted Tycoon 2FA, a phishing-as-a-service platform that helped criminals steal credentials and bypass multifactor authentication through adversary-in-the-middle techniques. Microsoft says it used a U.S. court order to seize 330 domains that hosted Tycoon’s control panels and many of its phishing pages.

Europol says it coordinated the cross-border effort through its European Cybercrime Centre and worked with law enforcement in Latvia, Lithuania, Portugal, Poland, Spain, and the United Kingdom to seize infrastructure in their jurisdictions.

Partners across the private sector supported the action with telemetry and infrastructure leads. Proofpoint says it provided a declaration that supported Microsoft’s civil filing and helped document Tycoon 2FA activity and infrastructure.

Microsoft Alert

What Tycoon 2FA did

Tycoon 2FA sold turnkey phishing infrastructure that sat between victims and real login pages. The operator’s setup captured credentials and session tokens while the victim interacted with what looked like a normal Microsoft 365 or Gmail sign-in flow. Microsoft says the service enabled large-scale impersonation and initial access.

Europol describes Tycoon 2FA as a criminal service that enabled MFA bypass and unauthorized account access, driven by tens of millions of phishing emails per month and broad global targeting.

Key details

ItemDetails
PlatformTycoon 2FA (phishing-as-a-service)
Core techniqueAdversary-in-the-middle phishing to capture credentials and session tokens
Disruption leadMicrosoft Digital Crimes Unit
Domains seized330 domains tied to control panels and phishing pages
Law enforcement coordinationEuropol EC3 with multiple European partners
Primary impactCredential theft, session hijacking, MFA bypass

What law enforcement and Microsoft actually seized

Microsoft says the seized domains now show a court-authorized splash page, and it framed the action as a coordinated disruption of the platform’s backbone infrastructure. Coinbase confirms the same outcome and says Microsoft seized domains that powered Tycoon’s operations, including domains that hosted control panels and certain phishing pages.

Europol emphasizes coordination and operational execution across borders, with EC3 acting as the central hub to share intelligence and translate it into action with affected countries.

Phishing Volume (Source: Microsoft)

Why this takedown matters

Phishing kits like Tycoon 2FA thrive because they lower the skill bar. A buyer can rent infrastructure, pick templates, and run campaigns without building proxy tooling from scratch. That model also scales quickly because operators rotate domains and host content across multiple providers.

This disruption should raise operational costs for the ecosystem, at least temporarily. It can also produce investigative value, because coordinated seizures often preserve backend data that helps investigators map affiliates, infrastructure, and payment flows. Europol explicitly points to coordinated action and intelligence sharing across jurisdictions as a core part of the operation.

What defenders should do next

  • Enforce phishing-resistant MFA where possible, especially FIDO2 and passkeys for high-risk users.
  • Tighten conditional access rules for session-token abuse, including device compliance, impossible travel controls, and risk-based sign-in policies.
  • Monitor for reverse-proxy phishing signals such as unusual sign-in URLs, abnormal authentication redirects, and rapid token reuse.
  • Block and alert on newly seen look-alike domains that mimic identity providers, even when the pages render correctly.
Tycoon 2FA Phishing Kit Dashboard (Source: Microsoft)

Practical detection notes

SignalWhy it matters
Sudden spike in logins that complete without the usual device patternsSession tokens often remove normal friction points
Multiple users clicking the same newly registered domainPhaaS campaigns reuse infrastructure across victims
Conditional access “passed” but device posture looks wrongAiTM kits can ride real sessions while the device stays unknown
Login page served from nonstandard hostnamesTycoon-style kits often host convincing templates on rotating domains

FAQ

What is Tycoon 2FA?

It is a phishing-as-a-service platform that provided infrastructure to steal credentials and hijack sessions, allowing MFA bypass via adversary-in-the-middle tactics.

What did the operation take down?

Microsoft says it seized 330 domains tied to Tycoon 2FA control panels and phishing pages under a U.S. court order, while Europol coordinated additional infrastructure seizures with European partners.

Does this end Tycoon 2FA?

Disruptions can break active infrastructure and reduce volume, but operators and affiliates often rebuild. Treat this as a chance to harden identity controls and hunt for related campaign remnants.

Which organizations helped?

Microsoft and Europol list broad public-private coordination. Proofpoint says it supported the civil filing with a declaration about Tycoon activity, and Coinbase says it partnered with Microsoft on the coordinated disruption.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages