A major phishing-as-a-service platform used for bypassing multi-factor authentication and large-scale compromise of accounts has been disrupted following a coordinated international operation supported by Europol, which led to the removal of 330 domains from the Tycoon 2FA infrastructure.
In brief
Tycoon 2FA provided cybercriminals with a subscription-based toolkit designed to intercept authentication sessions in real-time and gain unauthorized access to online accounts, including those additionally protected. The operation was coordinated by Europol through the European Cybercrime Centre (EC3) and involved law enforcement authorities and private sector actors. A total of 330 domains that formed the core infrastructure of the service, including phishing pages and control panels, were removed. The technical disruption was led by Microsoft, while operational measures were carried out by authorities from Latvia, Lithuania, Portugal, Poland, Spain, and the United Kingdom. The platform had been active at least since August 2023 and was described as one of the largest phishing operations in the world. Tycoon 2FA generated tens of millions of phishing emails per month and facilitated unauthorized access to nearly 100,000 organizations globally, including schools, hospitals, and public institutions. By mid-2025, Tycoon 2FA accounted for approximately 62% of all phishing attempts blocked by Microsoft.
Tycoon 2FA is described as a subscription-based service that provided cybercriminals with a set of tools designed to intercept authentication sessions in real-time and allow unauthorized access to online accounts, including accounts protected by additional layers of security. The tool was used to bypass multi-factor authentication and compromise accounts on a large scale.
The disruption operation was carried out by law enforcement authorities and private sector partners, under the coordination of Europol through the European Cybercrime Centre. As part of this action, 330 domains that formed the core infrastructure of the service, including phishing pages and control panels, were removed. The technical disruption was led by Microsoft, with the support of a coalition of private partners, while the seizure of infrastructure and other operational measures were conducted by authorities from Latvia, Lithuania, Portugal, Poland, Spain, and the United Kingdom.
Europol states that the platform, active at least since August 2023, was among the largest phishing operations worldwide. Tycoon 2FA allowed "thousands of cybercriminals" to gain covert access to email accounts and cloud services, and at scale generated "tens of millions of phishing emails each month." The institution indicates that the platform facilitated unauthorized access to "nearly 100,000 organizations" worldwide, including schools, hospitals, and public institutions.
In the presented assessment, by mid-2025, Tycoon 2FA represented "approximately 62% of all phishing attempts blocked by Microsoft."
The operation was built around public-private cooperation. Europol specifies that the investigation began after Trend Micro provided information, and Europol disseminated this information through advisory groups and operational networks of EC3, which allowed for the development of a coordinated operational strategy. Some members of the advisory groups were then integrated into the investigation to support the disruption action.
Europol states that, through the Cyber Intelligence Extension Programme, Microsoft and Trend Micro worked alongside law enforcement authorities, providing technical expertise and infrastructure analysis. The institution describes its role as a "central hub" among private partners and investigators, to ensure that information was shared with affected countries and transformed into coordinated operational action.
The list of mentioned partners includes Cloudflare, Coinbase, Intel471, Microsoft, Proofpoint, Shadowserver Foundation, SpyCloud, and Trend Micro. The national authorities listed in the communication include the State Police of Latvia, the Criminal Police Office of Lithuania, the Judicial Police of Portugal, the Central Cybercrime Combat Office of Poland, the National Police and Guardia Civil of Spain, and the National Crime Agency of the United Kingdom.
Europol describes the Cyber Intelligence Extension Programme as a mechanism that strengthens public-private cooperation in combating cybercrime, allowing private sector partners to contribute actionable information for operational outcomes. The programme is presented as "the first of its kind" and brings together experts from the private sector who temporarily work alongside analysts and investigators from EC3 in The Hague on specific projects.
The operation is also presented within EMPACT, the EU's multidisciplinary platform against criminal threats, which coordinates strategic and operational cooperation among national authorities, institutions, EU bodies, and international partners, in four-year cycles, on common priorities.
In brief
Tycoon 2FA provided cybercriminals with a subscription-based toolkit designed to intercept authentication sessions in real-time and gain unauthorized access to online accounts, including those additionally protected. The operation was coordinated by Europol through the European Cybercrime Centre (EC3) and involved law enforcement authorities and private sector actors. A total of 330 domains that formed the core infrastructure of the service, including phishing pages and control panels, were removed. The technical disruption was led by Microsoft, while operational measures were carried out by authorities from Latvia, Lithuania, Portugal, Poland, Spain, and the United Kingdom. The platform had been active at least since August 2023 and was described as one of the largest phishing operations in the world. Tycoon 2FA generated tens of millions of phishing emails per month and facilitated unauthorized access to nearly 100,000 organizations globally, including schools, hospitals, and public institutions. By mid-2025, Tycoon 2FA accounted for approximately 62% of all phishing attempts blocked by Microsoft.
Tycoon 2FA is described as a subscription-based service that provided cybercriminals with a set of tools designed to intercept authentication sessions in real-time and allow unauthorized access to online accounts, including accounts protected by additional layers of security. The tool was used to bypass multi-factor authentication and compromise accounts on a large scale.
The disruption operation was carried out by law enforcement authorities and private sector partners, under the coordination of Europol through the European Cybercrime Centre. As part of this action, 330 domains that formed the core infrastructure of the service, including phishing pages and control panels, were removed. The technical disruption was led by Microsoft, with the support of a coalition of private partners, while the seizure of infrastructure and other operational measures were conducted by authorities from Latvia, Lithuania, Portugal, Poland, Spain, and the United Kingdom.
Europol states that the platform, active at least since August 2023, was among the largest phishing operations worldwide. Tycoon 2FA allowed "thousands of cybercriminals" to gain covert access to email accounts and cloud services, and at scale generated "tens of millions of phishing emails each month." The institution indicates that the platform facilitated unauthorized access to "nearly 100,000 organizations" worldwide, including schools, hospitals, and public institutions.
In the presented assessment, by mid-2025, Tycoon 2FA represented "approximately 62% of all phishing attempts blocked by Microsoft."
The operation was built around public-private cooperation. Europol specifies that the investigation began after Trend Micro provided information, and Europol disseminated this information through advisory groups and operational networks of EC3, which allowed for the development of a coordinated operational strategy. Some members of the advisory groups were then integrated into the investigation to support the disruption action.
Europol states that, through the Cyber Intelligence Extension Programme, Microsoft and Trend Micro worked alongside law enforcement authorities, providing technical expertise and infrastructure analysis. The institution describes its role as a "central hub" among private partners and investigators, to ensure that information was shared with affected countries and transformed into coordinated operational action.
The list of mentioned partners includes Cloudflare, Coinbase, Intel471, Microsoft, Proofpoint, Shadowserver Foundation, SpyCloud, and Trend Micro. The national authorities listed in the communication include the State Police of Latvia, the Criminal Police Office of Lithuania, the Judicial Police of Portugal, the Central Cybercrime Combat Office of Poland, the National Police and Guardia Civil of Spain, and the National Crime Agency of the United Kingdom.
Europol describes the Cyber Intelligence Extension Programme as a mechanism that strengthens public-private cooperation in combating cybercrime, allowing private sector partners to contribute actionable information for operational outcomes. The programme is presented as "the first of its kind" and brings together experts from the private sector who temporarily work alongside analysts and investigators from EC3 in The Hague on specific projects.
The operation is also presented within EMPACT, the EU's multidisciplinary platform against criminal threats, which coordinates strategic and operational cooperation among national authorities, institutions, EU bodies, and international partners, in four-year cycles, on common priorities.
Latest News
17:30
Four members of a football gallery have been arrested, being suspected of having assaulted a Pakistani citizen.
17:26
The Europol Union requests the authorities to invest in safe vehicles for police officers, after a police car caught fire during a pursuit.
17:26
Soprano Ileana Cotrubaș died at the age of 87.
17:25
Innovation in China: Police robots reduce traffic violations by directing traffic
17:24
The interim Minister of Transport, Radu Miruță, stated that the situation of rail transport is twice as bad as it was 10 years ago.
See more news