Europol, Microsoft, and multiple cybersecurity firms coordinated a takedown of the subscription-based phishing-as-a-service platform Tycoon 2FA, which enabled attackers to impersonate users, deploy convincing phishing pages, and bypass multi-factor authentication to access email and cloud accounts. The operation seized 330 active domains, disrupted tens of millions of phishing emails affecting roughly 500,000 organizations and an estimated 96,000 victims since 2023, and led to legal action against suspected operators including Saad Fridi. #Tycoon2FA #Microsoft
Keypoints
- Tycoon 2FA is a subscription-based phishing-as-a-service platform that enabled real-time capture of credentials and authentication codes to bypass MFA.
- Microsoft reported Tycoon 2FA was responsible for about 62% of the phishing attempts it blocked last year.
- The platform sent tens of millions of phishing emails monthly, targeting roughly 500,000 organizations and around 96,000 victims since 2023.
- Law enforcement in multiple European countries and security firms seized 330 active Tycoon 2FA domains, including control panels and phishing pages.
- Legal action has been taken against suspected operators, including alleged main developer Saad Fridi in Pakistan.
Read More: https://www.securityweek.com/tycoon-2fa-phishing-platform-dismantled-in-global-takedown/