Tycoon 2FA Dismantled: Europol-Led Operation Takes Down MFA-Bypass Phishing Platform Used by Thousands of Cybercriminals

A major phishing-as-a-service (PhaaS) platform used to bypass multi-factor authentication (MFA) and enable large-scale account compromise has been disrupted following a coordinated international operation supported by Europol's European Cybercrime Centre (EC3). The service, known as Tycoon 2FA, provided cybercriminals with a subscription-based toolkit designed to intercept live authentication sessions and gain unauthorized access to online accounts — including those protected by additional security layers. As part of the disruption, 330 domains forming the core infrastructure of the criminal service, including phishing pages and control panels, were taken down. According to Europol's official statement, the technical disruption was led by Microsoft with the support of a coalition of private partners, while seizure of infrastructure and other operational measures were carried out by law enforcement in Latvia, Lithuania, Portugal, Poland, Spain, and the United Kingdom.

What Was Tycoon 2FA?

Active since at least August 2023, Tycoon 2FA rapidly established itself as one of the largest phishing operations worldwide. The platform operated as an adversary-in-the-middle (AiTM) proxy service: rather than simply spoofing login pages, it intercepted live authentication sessions in real time, capturing session tokens after a victim had already completed MFA verification. This allowed subscribing criminals to access victim accounts even when those accounts were protected by one-time passwords, authenticator apps, or hardware tokens — rendering conventional MFA protections ineffective against the attack chain. The service was structured as a subscription toolkit sold to cybercriminals who lacked the technical capability to build such infrastructure themselves, dramatically lowering the barrier to sophisticated credential-theft operations.

At scale, Tycoon 2FA generated tens of millions of phishing emails per month and facilitated unauthorized access to nearly 100,000 organizations globally, including schools, hospitals, and public institutions. By mid-2025, the platform accounted for roughly 62% of all phishing attempts blocked by Microsoft — an extraordinary concentration that underscores how dominant a single PhaaS operator can become within the broader phishing ecosystem.

Inside the Operator Panel: A Commercial-Grade Criminal Dashboard

Technical analysis published by Microsoft's Security Research team provides an unusually detailed view into Tycoon 2FA's operator-facing infrastructure. The platform's admin panel was purpose-built for operational efficiency, providing subscribing criminals with real-time visibility into campaign performance and victim authentication outcomes — functionality comparable in sophistication to a legitimate SaaS analytics dashboard.

Tycoon 2FA operator admin panel dashboard showing victim account outcomes, credential capture statistics, and session cookie management
Figure 7 (via Microsoft Security Blog): The Tycoon 2FA operator panel dashboard.

Several elements of the panel dashboard are analytically significant. The top-level statistics display — Total Visits, Valid, Invalid, and SSO — gave operators an at-a-glance read of campaign effectiveness, distinguishing successful authentication captures (Valid) from failed or incomplete sessions (Invalid) and single sign-on flows (SSO). The donut chart breakdown visible in the screenshot shows a 66.7% valid capture rate against 33.3% invalid, a notably high success ratio indicative of well-crafted lure pages. A "Login Websites" bar chart tracked which services were being impersonated across active campaigns, with Microsoft dominating — consistent with Tycoon 2FA's primary focus on Microsoft 365 and Azure AD account compromise. Additional services visible include SecureServer, AD FS, and GoDaddy, reflecting the platform's multi-service impersonation capability.

The "Visitors By Country" heatmap provided geographic targeting intelligence, while the panel's lower section displayed a Valid Accounts table containing harvested credentials organized by email address, password, targeted service (Office365 is visible in the sample row), browser, IP address, country of origin, 2FA status, 2FA method, and cookie capture status. The "Get Cookie" button per row allowed operators to extract the captured session token on demand, enabling immediate unauthorized access to victim accounts without knowledge of the victim's MFA secret. A "Copy Zip Pass" and "Download" function allowed bulk credential export. The visible sample entry — an Office365 account accessed via Chrome from IP 62.93.164.75 (New Zealand), captured on December 18, 2025, with 2FA marked as "No" — illustrates the granularity of victim data available to operators. The panel also displayed the active phishing URL and a session timer tracking how long a victim had been engaged with the lure page, enabling operators to monitor live sessions in near-real-time. Captured credentials and session cookies could additionally be forwarded to Telegram for immediate operator notification.

How the Investigation Unfolded: Intelligence-Led Disruption

The operation originated from intelligence shared by Trend Micro, which identified and analyzed Tycoon 2FA's infrastructure and operational patterns. Europol disseminated this intelligence through its EC3 Advisory Groups and operational networks, enabling a coordinated operational strategy to be developed across participating jurisdictions. Through Europol's Cyber Intelligence Extension Programme (CIEP), Microsoft and Trend Micro worked alongside law enforcement authorities, providing technical expertise and infrastructure analysis throughout the investigative phase. Europol acted as the central coordination hub between private partners and investigators, ensuring that intelligence was shared with affected countries and translated into synchronized operational action on the disruption day.

Public-Private Partnership Architecture

The Tycoon 2FA takedown represents one of the most structurally sophisticated public-private coordination efforts yet applied to a PhaaS platform. Law enforcement participation included:

Private sector partners engaged through Europol's CIEP framework included Cloudflare, Coinbase, Intel471, Microsoft, Proofpoint, Shadowserver Foundation, SpyCloud, and Trend Micro. The breadth of this coalition — spanning domain infrastructure providers, cryptocurrency exchanges, threat intelligence vendors, and email security firms — reflects the multi-layer nature of modern PhaaS infrastructure and the cross-sector expertise required to map and dismantle it.

Europol's Cyber Intelligence Extension Programme (CIEP)

The Tycoon 2FA operation is the first publicly confirmed major operational result attributable to Europol's Cyber Intelligence Extension Programme (CIEP) — a first-of-its-kind framework that embeds private-sector experts temporarily alongside EC3 analysts and investigators in The Hague on specific operational projects. The CIEP model bridges the intelligence gap between the private sector — which often detects and analyzes criminal infrastructure first — and law enforcement, which holds the legal authority to seize and disrupt it. Through this framework, Europol facilitates cross-border disruption of criminal infrastructure, enables operational deconfliction across jurisdictions, and ensures timely intelligence sharing on emerging threats and criminal methods.

Technical Significance: Why MFA Bypass at Scale Matters

The core technical capability of Tycoon 2FA — adversary-in-the-middle interception of authenticated sessions — represents a qualitatively more dangerous threat than traditional credential phishing. Conventional MFA deployments defend against static credential theft: even if a username and password are captured, an attacker cannot access the account without the second factor. AiTM platforms like Tycoon 2FA subvert this model entirely by proxying the full authentication exchange in real time and harvesting the resulting session cookie after MFA has been successfully completed by the victim. The resulting token grants full account access without the attacker needing to know the victim's MFA secret. At the scale Tycoon 2FA operated — nearly 100,000 targeted organizations, tens of millions of monthly phishing emails — this capability posed a systemic risk to organizations that had deployed standard TOTP-based MFA as their primary defense.

Intelligence Assessment and Recommendations

The dismantlement of Tycoon 2FA removes a disproportionately large share of the global PhaaS threat surface. However, IntelFusions assesses with moderate confidence that the underlying criminal demand for MFA-bypass PhaaS infrastructure will persist, and that alternative platforms or reconstituted successors will absorb displaced subscribers within weeks to months. Organizations should treat this takedown as a window of reduced threat intensity rather than a permanent resolution. Defensively, the demonstrated limits of TOTP-based MFA against AiTM attacks should prompt security teams to evaluate phishing-resistant MFA standards such as FIDO2/WebAuthn passkeys, which are architecturally immune to session-token interception. Conditional access policies evaluating device compliance, IP reputation, and session anomalies provide additional detection layers for AiTM-sourced unauthorized access.

This article is published for threat intelligence purposes. IntelFusions is not affiliated with any threat actor group. Claims described herein have not been independently verified unless explicitly stated.

Read the full analysis on IntelFusions