The infrastructure that hosted the Tycoon2FA phishing service has been taken down by an alliance of IT companies and law enforcement agencies. At least temporarily, this removes cybercriminals’ access to a powerful tool that allowed them to bypass defenses multi-factor authentication . Europol , which coordinated the operation, said the technical disruption was led by Microsoft , which secured a US court order to seize 330 active domains that powered Tycoon2FA’s central infrastructure (including control panels and fake login pages).

At the same time, law enforcement authorities in Latvia, Lithuania, Portugal, Poland, Spain, and the United Kingdom seized the service's infrastructure in their countries.
Other IT companies involved in the operation included Cloudflare, Coinbase, Intel471, Proofpoint, Shadowserver Foundation, SpyCloud, and Trend Micro.
Tycoon2FA: A powerful and dangerous phishing kit
Microsoft noted that, by mid-2025, Tycoon2FA accounted for about 62% of all phishing attempts it had blocked on its own. At one point, it had intercepted more than 30 million emails in a single month.
See also: LeakBase: Authorities dismantle stolen data exchange forum
It believes that Tycoon2FA, which was sold to malicious users as a phishing-as-a-service, was linked to an estimated 96,000 different phishing victims worldwide as of 2023, including more than 55,000 Microsoft customers. The company said that Tycoon2FA combined convincing phishing templates, realistic landing pages , and actual password and authentication code into an easy-to-use package that scaled quickly.
“By lowering the technical barrier to entry, it allowed criminals with limited experience to conduct sophisticated impersonation campaigns,” Microsoft said in a blog post. It noted that Tycoon2FA’s platform allowed malicious users to impersonate trusted tokens, mimicking login pages for services like Microsoft 365, OneDrive, Outlook, SharePoint, and Gmail.
Criminals could also gain access to sensitive information, even after passwords were reset, by intercepting session cookies created during the authentication process while simultaneously recording user credentials (unless active sessions and tokens were explicitly revoked). The intercepted multi-factor authentication (MFA) codes were then transmitted through Tycoon2FA's proxy servers to the authentication service.

Do not become complacent
This takedown is the latest in a series of collaborative efforts by the IT industry and law enforcement to tackle IT infrastructure . However, experts warned CSOs and information security leaders not to rest on their laurels. Cybercrime is so profitable that either a distribution of this tool will appear elsewhere, or another tool will take its place.
“Phishing tools designed to bypass reverse proxies continue to evolve,” noted Robert Beggs, head of the Canadian incident response firm Digital Defence. “Commercial variants like EvilProxy are commonly found online, and open-source tools like EvilGinx, Modlishka, EvilPunch are becoming the choice of attackers.”
Johannes Ullrich, dean of research at the SANS Institute, noted that access brokers, such as Tycoon2FA, are typically less susceptible to domain takeovers than malware operators who use domains for their command-and-control infrastructure.
See also: Hacked site cPanels are sought after in cybercrime markets
“It will probably take some time for them to rebuild the domains they will use in their operation,” he said in an email, “but I doubt they will disappear. On the other hand, there is reason to be happy: at least a temporary relief from Tycoon2FA phishing emails.” He added: “CSOs should, however, focus on identity security, particularly authentication technologies that are resistant to phishing. Multi -factor authentication is not sufficient if it is still vulnerable to phishing. A recently developed tool, Starkiller, has added yet another option for attackers to exploit inadequate MFA settings.”
Beggs pointed out that Tycoon2FA owes its success to its simple-to-use reverse proxy-based system . This configuration allows it to bypass the multi-factor authentication that most organizations rely on to protect against phishing attacks.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The reverse proxy allows the hostile program, the attacker, to essentially sit in the middle of a transaction and inject access credentials and cookies.

Strict defenses are required
CSOs should implement strict defenses against tools that use reverse proxies, including strengthening email filtering by enforcing DMARC, DKIM, and SPF.
They should also enforce secure session management using client-bound session tokens associated with the device or TLS certificates. They should ensure continuous validation, issuing a new challenge when the device fingerprint changes and using short-lived cookies. They should monitor network traffic for signs of man-in-the-middle behavior, such as inconsistent host headers, proxy-added headers, and time differences between client and server flows.
It is also necessary to adopt phishing-resistant MFA with tools such as FIDO2/WebAuthn hardware keys, passkeys, or certificate-based authentication.
Because authentication is tied to the origin (domain) and cryptographic challenges cannot be reproduced through a reverse proxy, these methods cannot be bypassed.
How the phishing service worked
Tycoon2FA’s phishing services were advertised and sold to cybercriminals through apps like Telegram and Signal. Prices varied by service, but phishing kits started at $120 for 10 days of access to an admin panel, which acted as a single dashboard for configuring, monitoring, and improving campaigns.
See also: Microsoft: OAuth phishing attacks are evolving
For defenders unaware of how comprehensive these SaaS criminal operations can be, here’s a summary of Tycoon2FA’s service: Campaign operators could configure a broad set of campaign parameters that control how phishing content is delivered and presented to targets. Key settings include lure template selection and branding customization, redirect routing, MFA interception behavior, CAPTCHA appearance and logic, attachment generation, and export configuration.

Tycoon2FA would create a large number of sundomains for individual phishing campaigns, use them for a while, then abandon them and create new ones. They could also configure how the malicious content. Options include creating EML files, PDFs, and QR codes, offering multiple ways to package and distribute the phishing content.
Operators could track valid and invalid login attempts, MFA usage, and session cookie capture, with victim data organized by attributes such as targeted service, browser, location, and authentication status. The captured credentials and session cookies could be viewed or downloaded directly within the panel and/or pushed to Telegram for near-real-time monitoring.
The above features, combined with its affordability and ease of use, made Tycoon2FA a persistent and significant threat to both consumer and business accounts.
