Microsoft’s Digital Crimes Unit (DCU), Europol, and multiple private-sector partners disrupted the Tycoon 2FA phishing-as-a-service (PhaaS) operation, an adversary-in-the-middle (AiTM) kit used to bypass multifactor authentication (MFA) at scale. The action included infrastructure seizures (reported as hundreds of domains, including 330 in one account) and takedown of panels and phishing pages under legal process, targeting a service active since 2023 and associated by Microsoft with the threat actor Storm-1747. Tycoon 2FA was used to impersonate common enterprise identity targets (notably Microsoft 365 and Gmail) and to capture credentials plus session cookies/tokens, enabling account takeover even after password resets unless sessions/tokens are revoked.
Reporting and partner telemetry described Tycoon 2FA as a high-volume AiTM threat responsible for tens of millions of phishing messages and broad cross-sector targeting (including education and healthcare). Microsoft stated Tycoon 2FA represented a large share of the phishing it blocked and tied activity to a substantial victim set, while Proofpoint characterized it as the highest-volume AiTM phishing threat in its data and said the disruption—supported by organizations including Cloudflare, Coinbase, Health-ISAC, and others—would materially impact Tycoon 2FA-related infrastructure and actor activity. Separately, LastPass warned of a distinct phishing campaign using spoofed security alerts and a lookalike domain (verify-lastpass[.]com) to steal master passwords; this is unrelated to the Tycoon 2FA disruption.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
By 2026-04-17, Barracuda and Proofpoint reported that former Tycoon 2FA operators or customers appeared to be reusing Tycoon-linked tooling, code artifacts, and tradecraft in device code phishing campaigns. The researchers said abuse of legitimate device-login flows had grown since late 2025 and surged in recent weeks as the Tycoon ecosystem fragmented after the takedown.
On 2026-04-17, Barracuda said Tycoon 2FA-related phishing fell 77% after the March takedown but still exceeded two million attacks per month. The company assessed that Tycoon 2FA tools and techniques had spread into cloned deployments and competing kits including Mamba 2FA, EvilProxy, Sneaky 2FA, and Whisper 2FA.
After the March 4, 2026 domain seizures, Tycoon 2FA operators rapidly rebuilt infrastructure and resumed cloud-account phishing, with activity returning to roughly early-2026 levels within days. Researchers observed continued targeting of Microsoft 365 and other cloud services, including new IPv6 infrastructure and the same core AiTM tactics used before the disruption.
Following the takedown announcement, Microsoft, Proofpoint, Intel 471, and other partners published detailed analyses of Tycoon 2FA’s infrastructure, evasion methods, delivery techniques, and post-compromise risks. These disclosures included hunting guidance, indicators, and recommendations such as phishing-resistant MFA and stronger session controls.
On March 4, 2026, Shadowserver issued a one-off 'Tycoon 2FA Domains Special Report' to 237 national CSIRTs. The report contained 25,206 domain-related events to support historical hunting and response following the disruption.
On March 4, 2026, Microsoft, Europol, national law-enforcement agencies, and industry partners announced a coordinated disruption of Tycoon 2FA. The operation seized or took down 330 domains tied to phishing pages and control panels, with related infrastructure seizures across several European countries.
Microsoft and Health-ISAC filed a civil lawsuit in the U.S. District Court for the Southern District of New York naming alleged creator Saad Fridi and unnamed associates. The court action enabled legal measures used in the subsequent disruption of Tycoon 2FA infrastructure.
By January 2026, reporting indicated Tycoon 2FA activity had dropped sharply, aligning with ongoing intelligence gathering and infrastructure-seizure efforts by public- and private-sector partners. Some sources estimate the platform sent roughly 87.5 million phishing messages from October 2025 through January 2026 before the decline.
By mid-2025, Microsoft said Tycoon 2FA accounted for about 62% of phishing attempts it blocked, including more than 30 million emails in a single month. The platform was also associated with successful phishing of more than 100 Health-ISAC member organizations and disruptions affecting institutions in New York.
Through 2024 and 2025, Tycoon 2FA scaled into one of the most widespread AiTM phishing services, marketed via channels such as Telegram and Signal with admin panels, templates, hosting support, and campaign tooling. Microsoft and other researchers linked it to tens of millions of phishing emails per month and impacts across healthcare, education, and other sectors worldwide.
Tycoon 2FA emerged in August 2023 as a phishing-as-a-service adversary-in-the-middle kit designed to steal credentials and session cookies to bypass MFA and take over accounts. It targeted services such as Microsoft 365, Outlook, Gmail, and other cloud identity platforms.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
23 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcemicrosoft.com
Open sourcescworld.com
Open sourceitpro.com
Open sourcemicrosoft.com
Open sourcecsoonline.com
Open sourceintel471.com
Open sourceproofpoint.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.