Advertisement Subscribe to our daily newsletter. Subscribe Close Cybercrime Global coalition dismantles Tycoon 2FA phishing kit Microsoft, which led the effort, said it seized 330 domains that powered the phishing platform’s core infrastructure. The alleged creator was also named in a civil complaint. By Matt Kapko March 4, 2026 Listen to this article 0:00 Learn more. This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment. Microsoft and authorities dismantled Tycoon 2FA's infrastructure. A seizure notice is displayed on of the phishing platform's domains March 4, 2026. (Microsoft) Tycoon 2FA, a major phishing kit and platform that allowed low-skilled cybercriminals to bypass multifactor authentication and conduct large-scale adversary-in-the-middle attacks, was dismantled Wednesday by a global coalition of security companies and law enforcement agencies. Microsoft, which led the effort alongside Europol and authorities from six countries and 11 security firms or organizations, said it seized 330 domains that powered Tycoon 2FA’s core infrastructure, including control panels and fraudulent login pages. The platform, which emerged in August 2023, was responsible for tens of millions of phishing messages that reached more than 500,000 organizations globally each month, according to Microsoft Threat Intelligence. Thousands of cybercriminals used Tycoon 2FA to break into email and online services, including Microsoft 365, Outlook, SharePoint, OneDrive and Google services. “By mid‑2025, Tycoon 2FA accounted for approximately 62% of all phishing attempts Microsoft blocked, including more than 30 million emails in a single month. That placed Tycoon 2FA among the largest phishing operations globally,” Steven Masada, assistant general counsel at Microsoft’s Digital Crimes Unit, said in a blog post about the takedown. Advertisement “Despite extensive defenses, the service is linked to an estimated 96,000 distinct phishing victims worldwide since 2023, including more than 55,000 Microsoft customers,” Masada added. The phishing kit, which was developed and advertised by a group Microsoft tracks as Storm-1747, was sold to cybercriminals on Telegram and Signal for $350 a month. The platform provided core components for phishing on a single dashboard that allowed cybercriminals to configure, track and refine their campaigns. The platform also provided cybercriminals with pre-built templates, attachment files for common phishing lures, domain and hosting configuration and redirect logic, Microsoft said. The monthly volume of phishing messages attributed to Tycoon 2FA peaked at more than 30 million messages in November 2025. Organizations in education and health care were hit hardest by phishing attacks enabled by Tycoon 2FA. More than 100 members of Health-ISAC, a co-plaintiff in the court case filed in the U.S. District Court for the Southern District of New York, were successfully phished, Masada said. Two hospitals, six schools and three universities in New York confronted attempts or successful compromises via Tycoon 2FA, resulting in incidents that disrupted operations, diverted resources and delayed patient care, he added. Advertisement Microsoft and Health-ISAC filed a civil complaint against alleged creator Saad Fridi and four unnamed associates, demanding a $10 million injunction, for developing, running and selling Tycoon 2FA. The court order allowed Microsoft to dismantle and take ownership of Tycoon 2FA’s technical infrastructure. Authorities from Latvia, Lithuania, Portugal, Poland, Spain and the United Kingdom assisted with the operation alongside Cloudflare, Coinbase, Crowell & Moring, eSentire, Intel 471, Proofpoint, Resecurity, Shadowserver, SpyCloud and Trend Micro. Selena Larson, staff threat researcher at Proofpoint who provided a formal declaration in support of the court order , said Tycoon 2FA was responsible for the highest volume of adversary-in-the-middle phishing attacks observed by Proofpoint. “Tycoon was the biggest MFA phishing threat in our data, and we anticipate seeing a significant decrease after this operation,” she told CyberScoop. “Many customers will find their hacking tool is no longer working, and even if Tycoon 2FA is able to create new domains and infrastructure, the brand will be significantly harmed, with customers either purchasing less effective phishing kit, or potentially rethinking their life choices and getting out of the game,” Larson added. Advertisement Tycoon 2FA’s easy-to-use and robust capabilities contributed to its popularity, researchers said. The platform’s codebase was updated regularly and operators generated a high volume of subdomains for brief periods before abandoning them and moving on to new domains. Researchers said the rapid turnover and shifts to temporary infrastructure complicated efforts to detect and block new campaigns. The Tycoon 2FA takedown follows a recent wave of cybercrime crackdowns , including actions against Racoon0365 and the Lumma Stealer infostealer operation , which infected about 10 million systems . Written by Matt Kapko Matt Kapko is a reporter at CyberScoop. His beat includes cybercrime, ransomware, software defects and vulnerability (mis)management. The lifelong Californian started his journalism career in 2001 with previous stops at Cybersecurity Dive, CIO, SDxCentral and RCR Wireless News. Matt has a degree in journalism and history from Humboldt State University. In This Story Cloudflare Coinbase cybercrime eSentire Europol Health-ISAC Intel 471 Latvia Lithuania Microsoft Microsoft Digital Crimes Unit Microsoft Threat Intelligence Poland portugal Proofpoint Resecurity Shadowserver Spain SpyCloud Trend Micro United Kingdom (U.K.) Share Facebook LinkedIn Twitter Copy Link Advertisement Advertisement More Like This Phobos ransomware leader pleads guilty, faces up to 20 years in prison By Matt Kapko Authorities from 14 countries shut down major cybercrime forum LeakBase By Matt Kapko Microsoft warns North Korean threat groups are scaling up fake worker schemes with generative AI By Matt Kapko Advertisement Top Stories DHS CISO, deputy CISO exit amid reported IT leadership overhaul By Derek B. Johnson Lindsey Wilkinson Congress looks to revive critical cyber program for rural electric utilities By Derek B. Johnson Advertisement More Scoops RaccoonO365 login page (Credit: Microsoft’s Digital Crimes Unit) Microsoft seizes hundreds of phishing sites tied to massive credential theft operation The company acted on a court order and collaborated with Cloudflare to seize RaccoonO365’s infrastructure, which was used to steal credentials from organizations in 94 countries. By Matt Kapko Latest Podcasts What happens if CISA 2015 lapses? A plea to improve quantum security in the federal government T-Mobile’s Eric Jensen on the challenge of securing vast supply chains Datadog’s Emilio Escobar on compliance-first AI Government FBI targeted with ‘suspicious’ activity on its networks HHS updates a free risk tool to help hospitals size up their cybersecurity exposure CISA CIO Robert Costello exits agency The FBI’s cyber chief is using Winter SHIELD to accelerate China prep, threat intelligence sharing Technology Cisco reveals 2 max-severity defects in firewall management software Google addresses actively exploited Qualcomm zero-day in fresh batch of 129 Android vulnerabilities Vulnerabilities grew like weeds in 2025, but only 1% were weaponized in attacks Chinese group’s ChatGPT use reveals worldwide harassment campaign against critics Threats Attackers are using your network against you, according to Cloudflare Possible U.S.-developed exploits linked to first known ‘mass’ iOS attack Project Compass is Europol's new playbook for taking on The Com Governments issue warning over Cisco zero-day attacks dating back to 2023 Policy Across party lines and industry, the verdict is the same: CISA is in trouble State Dept. official says post-quantum transition plans will outlive current leadership HHS burrows into identifying risks to health sector from third-party vendors ONCD official says Trump administration aims to bolster AI use for defense without increasing risk
Tycoon 2FA was a phishing-as-a-service platform enabling adversary-in-the-middle attacks to bypass multi-factor authentication by providing criminals with pre-built templates, hosting, and campaign management. The platform, responsible for tens of millions of monthly phishing messages and accounting for approximately 62% of Microsoft-blocked phishing attempts by mid-2025, has been dismantled by a global coalition led by Microsoft and Europol, resulting in the seizure of 330 core infrastructure domains.