Skip to content

Tycoon2FA Shutdown Reduces Classic Phishing Attacks by 92 Percent

The Bottom Line: While the Tycoon2FA shutdown reduced classic phishing by 92 percent, attackers are pivoting to automated BEC and Teams-based social engineering.

The shutdown of the Tycoon2FA phishing-as-a-service platform has reduced phishing volume by 92 percent and is forcing attackers to adopt new delivery methods. Microsoft documents in its Q2 2026 threat landscape report that attacking groups are shifting in parallel to QR code and CAPTCHA phishing, business email compromise, and Microsoft Teams-based social engineering.

Microsoft has documented in its report “Email threat landscape: Q2 2026 trends and insights” that phishing volume associated with the Tycoon2FA platform fell by 92 percent following its shutdown. Over the monthly period, Tycoon2FA-related phishing volume declined by 15 percent in March, 22 percent in April, then 74 percent in May (1.5 million messages) and an additional 20 percent in June (1.2 million messages) – the lowest volume in at least one year.

QR code phishing declined from 18.7 million attacks in March to 8.3 million in June; CAPTCHA phishing fell from 12 million to 2.2 million. These figures demonstrate that Tycoon2FA’s customer base did not migrate to replacement infrastructure. Meanwhile, business email compromise (BEC) grew by 121 percent between March and April, then declined to 3.9 million in June. The shutdown forced operators to rebuild hosting, domain registrations, and delivery mechanisms.

In response, attackers shifted their activities: Microsoft Teams was increasingly used as a social engineering channel, with a 19 percent increase in detected attacks from March to April. Simultaneously, Microsoft documented a highly automated BEC campaign that reached over 67,000 users through scripting, Amazon SES, and engagement tracking. A separate campaign targeted 107,000 users and abused Microsoft authentication flows, Teams archive recording, and ICS calendar invites to obfuscate malware delivery.

Microsoft recommends organizations complement email filtering with phishing-resistant authentication such as passkeys and phishing-resistant MFA. Additionally, Exchange Online Protection and Microsoft Defender for Office 365 should be strengthened with Safe Links and Zero-Hour Auto Purge (ZAP) – which removes malicious emails already delivered before they are read.


Source: www.csoonline.com · Published 24 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: