search icon
search icon
Flag Arrow Down
Română
Română
Magyar
Magyar
English
English
Français
Français
Deutsch
Deutsch
Italiano
Italiano
Español
Español
Русский
Русский
日本語
日本語
中国人
中国人

Change Language

arrow down
  • Română
    Română
  • Magyar
    Magyar
  • English
    English
  • Français
    Français
  • Deutsch
    Deutsch
  • Italiano
    Italiano
  • Español
    Español
  • Русский
    Русский
  • 日本語
    日本語
  • 中国人
    中国人
Sections
  • News
  • Exclusive
  • INSCOP Surveys
  • Podcast
  • EU
  • Diaspora
  • Republic of Moldova
  • Politics
  • Economy
  • Current Affairs
  • International
  • Sport
  • Health
  • Education
  • IT&C knowledge
  • Arts & Lifestyle
  • Opinions
  • Elections 2025
  • Environment
About Us
Contact
Privacy policy
Terms and conditions
Quickly scroll through news digests and see how they are covered in different publications!
  • News
  • Exclusive
    • INSCOP Surveys
    • Podcast
    • EU
    • Diaspora
    • Republic of Moldova
    • Politics
    • Economy
    • Current Affairs
    • International
    • Sport
    • Health
    • Education
    • IT&C knowledge
    • Arts & Lifestyle
    • Opinions
    • Elections 2025
    • Environment
169 new news items in the last 24 hours
  1. Home
  2. EU

Europol coordinates the dismantling of Tycoon 2FA, a global phishing-as-a-service platform used to bypass multi-factor authentication.

2eu.brussels
whatsapp
facebook
linkedin
x
copy-link copy-link
5 March 2026, 13:42
main event image
EU
Foto: 2eu.brussels
google-preference

Always see our news on Google

A major phishing-as-a-service platform used for bypassing multi-factor authentication and large-scale compromise of accounts has been disrupted following a coordinated international operation supported by Europol, which led to the removal of 330 domains from the Tycoon 2FA infrastructure.

In brief

Tycoon 2FA provided cybercriminals with a subscription-based toolkit designed to intercept authentication sessions in real-time and gain unauthorized access to online accounts, including those additionally protected. The operation was coordinated by Europol through the European Cybercrime Centre (EC3) and involved law enforcement authorities and private sector actors. A total of 330 domains that formed the core infrastructure of the service, including phishing pages and control panels, were removed. The technical disruption was led by Microsoft, while operational measures were carried out by authorities from Latvia, Lithuania, Portugal, Poland, Spain, and the United Kingdom. The platform had been active at least since August 2023 and was described as one of the largest phishing operations in the world. Tycoon 2FA generated tens of millions of phishing emails per month and facilitated unauthorized access to nearly 100,000 organizations globally, including schools, hospitals, and public institutions. By mid-2025, Tycoon 2FA accounted for approximately 62% of all phishing attempts blocked by Microsoft.

Tycoon 2FA is described as a subscription-based service that provided cybercriminals with a set of tools designed to intercept authentication sessions in real-time and allow unauthorized access to online accounts, including accounts protected by additional layers of security. The tool was used to bypass multi-factor authentication and compromise accounts on a large scale.

The disruption operation was carried out by law enforcement authorities and private sector partners, under the coordination of Europol through the European Cybercrime Centre. As part of this action, 330 domains that formed the core infrastructure of the service, including phishing pages and control panels, were removed. The technical disruption was led by Microsoft, with the support of a coalition of private partners, while the seizure of infrastructure and other operational measures were conducted by authorities from Latvia, Lithuania, Portugal, Poland, Spain, and the United Kingdom.

Europol states that the platform, active at least since August 2023, was among the largest phishing operations worldwide. Tycoon 2FA allowed "thousands of cybercriminals" to gain covert access to email accounts and cloud services, and at scale generated "tens of millions of phishing emails each month." The institution indicates that the platform facilitated unauthorized access to "nearly 100,000 organizations" worldwide, including schools, hospitals, and public institutions.

In the presented assessment, by mid-2025, Tycoon 2FA represented "approximately 62% of all phishing attempts blocked by Microsoft."

The operation was built around public-private cooperation. Europol specifies that the investigation began after Trend Micro provided information, and Europol disseminated this information through advisory groups and operational networks of EC3, which allowed for the development of a coordinated operational strategy. Some members of the advisory groups were then integrated into the investigation to support the disruption action.

Europol states that, through the Cyber Intelligence Extension Programme, Microsoft and Trend Micro worked alongside law enforcement authorities, providing technical expertise and infrastructure analysis. The institution describes its role as a "central hub" among private partners and investigators, to ensure that information was shared with affected countries and transformed into coordinated operational action.

The list of mentioned partners includes Cloudflare, Coinbase, Intel471, Microsoft, Proofpoint, Shadowserver Foundation, SpyCloud, and Trend Micro. The national authorities listed in the communication include the State Police of Latvia, the Criminal Police Office of Lithuania, the Judicial Police of Portugal, the Central Cybercrime Combat Office of Poland, the National Police and Guardia Civil of Spain, and the National Crime Agency of the United Kingdom.

Europol describes the Cyber Intelligence Extension Programme as a mechanism that strengthens public-private cooperation in combating cybercrime, allowing private sector partners to contribute actionable information for operational outcomes. The programme is presented as "the first of its kind" and brings together experts from the private sector who temporarily work alongside analysts and investigators from EC3 in The Hague on specific projects.

The operation is also presented within EMPACT, the EU's multidisciplinary platform against criminal threats, which coordinates strategic and operational cooperation among national authorities, institutions, EU bodies, and international partners, in four-year cycles, on common priorities.

Sources

sursa imagine
2eu
Europol coordonează destructurarea Tycoon 2FA, o platformă globală de phishing-as-a-service folosită pentru ocolirea autentificării multi-factor

Latest News

22:55

Cristian Bușoi, Secretary of State at the Ministry of Energy, assures that Romanians will not receive double electricity bills for the same consumption next winter

22:48

Police conducted searches in a case involving card fraud after foreign tourists were allegedly deceived in the Old Town.

22:22

Radu Miruță announces measures for Romanian grain exports and denies that Ukrainian trains are being prioritized at the Port of Constanța

22:14

Marco Rubio urges Europe to “wake up from sleep” and strengthen its defense

21:54

Bulgaria invites Romania and Turkey for consultations after drone attacks on commercial vessels in the Black Sea

See more news

NEWS ON THE SAME TOPICS

event image
EU
Romania takes part in the operation that shut down KillSec’s infrastructure after around 1,000 suspected attacks
event image
EU
Europol reports 4,340 online addresses linked to an extremist network that recruits and exploits minors
event image
International
A drug investigation uncovered a global clandestine banking network, with 21 suspects arrested and assets worth €20 million identified
event image
EU
Six arrests in a network that moved migrants through Schengen airports using false identities
event image
EU
The EU sanctions Russian networks of cyber attacks that targeted critical infrastructure, public institutions, and essential services.
event image
International
The US, Bulgaria, Hungary and Romania have neutralized the infrastructure of the Sality malware
app preview
Personalized news feed, AI-powered search, and notifications in a more interactive experience.
app preview app preview
Europol destructurare Tycoon 2FA

Editor’s Recommendations

main event image
International
1 hour ago

International Energy Agency ready to release additional oil and diesel reserves

Sources
imagine sursa
imagine sursa
imagine sursa
imagine sursa
main event image
Exclusive
11 hours ago

ANALYSIS France’s overlapping crises and the lessons for Europe and Romania

app preview
Personalized news feed, AI-powered search, and notifications in a more interactive experience.
app preview
app store badge google play badge
  • News
  • Exclusive
  • INSCOP Surveys
  • Podcast
  • EU
  • Diaspora
  • Republic of Moldova
  • Politics
  • Economy
  • Current Affairs
  • International
  • Sport
  • Health
  • Education
  • IT&C knowledge
  • Arts & Lifestyle
  • Opinions
  • Elections 2025
  • Environment
  • About Us
  • Contact
Privacy policy
Cookies Policy
Terms and conditions
Open source licenses
All rights reserved Strategic Media Team SRL

Technology in partnership with

anpc-sal anpc-sol