A major phishing-as-a-service platform used for bypassing multi-factor authentication and large-scale compromise of accounts has been disrupted following a coordinated international operation supported by Europol, which led to the removal of 330 domains from the Tycoon 2FA infrastructure.
In brief
Tycoon 2FA provided cybercriminals with a subscription-based toolkit designed to intercept authentication sessions in real-time and gain unauthorized access to online accounts, including those additionally protected. The operation was coordinated by Europol through the European Cybercrime Centre (EC3) and involved law enforcement authorities and private sector actors. A total of 330 domains that formed the core infrastructure of the service, including phishing pages and control panels, were removed. The technical disruption was led by Microsoft, while operational measures were carried out by authorities from Latvia, Lithuania, Portugal, Poland, Spain, and the United Kingdom. The platform had been active at least since August 2023 and was described as one of the largest phishing operations in the world. Tycoon 2FA generated tens of millions of phishing emails per month and facilitated unauthorized access to nearly 100,000 organizations globally, including schools, hospitals, and public institutions. By mid-2025, Tycoon 2FA accounted for approximately 62% of all phishing attempts blocked by Microsoft.
Tycoon 2FA is described as a subscription-based service that provided cybercriminals with a set of tools designed to intercept authentication sessions in real-time and allow unauthorized access to online accounts, including accounts protected by additional layers of security. The tool was used to bypass multi-factor authentication and compromise accounts on a large scale.
The disruption operation was carried out by law enforcement authorities and private sector partners, under the coordination of Europol through the European Cybercrime Centre. As part of this action, 330 domains that formed the core infrastructure of the service, including phishing pages and control panels, were removed. The technical disruption was led by Microsoft, with the support of a coalition of private partners, while the seizure of infrastructure and other operational measures were conducted by authorities from Latvia, Lithuania, Portugal, Poland, Spain, and the United Kingdom.
Europol states that the platform, active at least since August 2023, was among the largest phishing operations worldwide. Tycoon 2FA allowed "thousands of cybercriminals" to gain covert access to email accounts and cloud services, and at scale generated "tens of millions of phishing emails each month." The institution indicates that the platform facilitated unauthorized access to "nearly 100,000 organizations" worldwide, including schools, hospitals, and public institutions.
In the presented assessment, by mid-2025, Tycoon 2FA represented "approximately 62% of all phishing attempts blocked by Microsoft."
The operation was built around public-private cooperation. Europol specifies that the investigation began after Trend Micro provided information, and Europol disseminated this information through advisory groups and operational networks of EC3, which allowed for the development of a coordinated operational strategy. Some members of the advisory groups were then integrated into the investigation to support the disruption action.
Europol states that, through the Cyber Intelligence Extension Programme, Microsoft and Trend Micro worked alongside law enforcement authorities, providing technical expertise and infrastructure analysis. The institution describes its role as a "central hub" among private partners and investigators, to ensure that information was shared with affected countries and transformed into coordinated operational action.
The list of mentioned partners includes Cloudflare, Coinbase, Intel471, Microsoft, Proofpoint, Shadowserver Foundation, SpyCloud, and Trend Micro. The national authorities listed in the communication include the State Police of Latvia, the Criminal Police Office of Lithuania, the Judicial Police of Portugal, the Central Cybercrime Combat Office of Poland, the National Police and Guardia Civil of Spain, and the National Crime Agency of the United Kingdom.
Europol describes the Cyber Intelligence Extension Programme as a mechanism that strengthens public-private cooperation in combating cybercrime, allowing private sector partners to contribute actionable information for operational outcomes. The programme is presented as "the first of its kind" and brings together experts from the private sector who temporarily work alongside analysts and investigators from EC3 in The Hague on specific projects.
The operation is also presented within EMPACT, the EU's multidisciplinary platform against criminal threats, which coordinates strategic and operational cooperation among national authorities, institutions, EU bodies, and international partners, in four-year cycles, on common priorities.
In brief
Tycoon 2FA provided cybercriminals with a subscription-based toolkit designed to intercept authentication sessions in real-time and gain unauthorized access to online accounts, including those additionally protected. The operation was coordinated by Europol through the European Cybercrime Centre (EC3) and involved law enforcement authorities and private sector actors. A total of 330 domains that formed the core infrastructure of the service, including phishing pages and control panels, were removed. The technical disruption was led by Microsoft, while operational measures were carried out by authorities from Latvia, Lithuania, Portugal, Poland, Spain, and the United Kingdom. The platform had been active at least since August 2023 and was described as one of the largest phishing operations in the world. Tycoon 2FA generated tens of millions of phishing emails per month and facilitated unauthorized access to nearly 100,000 organizations globally, including schools, hospitals, and public institutions. By mid-2025, Tycoon 2FA accounted for approximately 62% of all phishing attempts blocked by Microsoft.
Tycoon 2FA is described as a subscription-based service that provided cybercriminals with a set of tools designed to intercept authentication sessions in real-time and allow unauthorized access to online accounts, including accounts protected by additional layers of security. The tool was used to bypass multi-factor authentication and compromise accounts on a large scale.
The disruption operation was carried out by law enforcement authorities and private sector partners, under the coordination of Europol through the European Cybercrime Centre. As part of this action, 330 domains that formed the core infrastructure of the service, including phishing pages and control panels, were removed. The technical disruption was led by Microsoft, with the support of a coalition of private partners, while the seizure of infrastructure and other operational measures were conducted by authorities from Latvia, Lithuania, Portugal, Poland, Spain, and the United Kingdom.
Europol states that the platform, active at least since August 2023, was among the largest phishing operations worldwide. Tycoon 2FA allowed "thousands of cybercriminals" to gain covert access to email accounts and cloud services, and at scale generated "tens of millions of phishing emails each month." The institution indicates that the platform facilitated unauthorized access to "nearly 100,000 organizations" worldwide, including schools, hospitals, and public institutions.
In the presented assessment, by mid-2025, Tycoon 2FA represented "approximately 62% of all phishing attempts blocked by Microsoft."
The operation was built around public-private cooperation. Europol specifies that the investigation began after Trend Micro provided information, and Europol disseminated this information through advisory groups and operational networks of EC3, which allowed for the development of a coordinated operational strategy. Some members of the advisory groups were then integrated into the investigation to support the disruption action.
Europol states that, through the Cyber Intelligence Extension Programme, Microsoft and Trend Micro worked alongside law enforcement authorities, providing technical expertise and infrastructure analysis. The institution describes its role as a "central hub" among private partners and investigators, to ensure that information was shared with affected countries and transformed into coordinated operational action.
The list of mentioned partners includes Cloudflare, Coinbase, Intel471, Microsoft, Proofpoint, Shadowserver Foundation, SpyCloud, and Trend Micro. The national authorities listed in the communication include the State Police of Latvia, the Criminal Police Office of Lithuania, the Judicial Police of Portugal, the Central Cybercrime Combat Office of Poland, the National Police and Guardia Civil of Spain, and the National Crime Agency of the United Kingdom.
Europol describes the Cyber Intelligence Extension Programme as a mechanism that strengthens public-private cooperation in combating cybercrime, allowing private sector partners to contribute actionable information for operational outcomes. The programme is presented as "the first of its kind" and brings together experts from the private sector who temporarily work alongside analysts and investigators from EC3 in The Hague on specific projects.
The operation is also presented within EMPACT, the EU's multidisciplinary platform against criminal threats, which coordinates strategic and operational cooperation among national authorities, institutions, EU bodies, and international partners, in four-year cycles, on common priorities.
Latest News
08:29
The High Court of Cassation and Justice is expected to pronounce today the final decision in the case of outstanding salary rights for magistrates.
08:26
The South Korean Minister of Defense claims that North Korea possesses between 80 and 120 nuclear weapons, a figure significantly higher than the estimate of 57 put forward by Donald Trump.
08:06
The U.S. Treasury debt has reached $40.047 trillion, exceeding CBO estimates. The rapid increase in the deficit raises concerns in the financial markets.
07:59
The Washington Post: Russians withdraw billions from banks, fearing that Putin will confiscate their deposits to finance his war
07:46
Hungary: The construction of a riverbed threshold on the Danube has raised the water level by 15-20 cm, preventing the shutdown of the turbines at the Paks nuclear power plant.
See more news