Skip to content

Tycoon 2FA: Why the takedown of the phishing kit barely slows attackers down

Bottom line: Europol’s seizure of over 300 domains and Tycoon 2FA’s backend infrastructure only disrupts the attack wave short-term, as interchangeable infrastructure components keep the PhaaS business model viable.

In early 2026, Europol seized more than 300 domains and the backend infrastructure of the phishing-as-a-service platform Tycoon 2FA. However, analyses by Barracuda Research show that such takedowns hardly weaken the underlying criminal infrastructure in any lasting way.

Tycoon 2FA was among the best-known and most effective phishing-as-a-service offerings (PhaaS) in the underground and was responsible for more than nine million attacks per month. The platform allowed even less technically skilled actors to run phishing campaigns specifically designed to bypass multi-factor authentication (MFA), for instance by intercepting session tokens or one-time codes. In early 2026, Europol, as part of a coordinated action, seized more than 300 domains as well as the backend infrastructure used to operate the platform.

For security leaders, the real takeaway is not the takedown itself, but its limited effect. Threat insights from Barracuda Research show that PhaaS ecosystems like Tycoon 2FA are designed so that individual infrastructure components are interchangeable. Domains, hosting and backend systems can be replaced relatively quickly with new resources, while core functionality, customer relationships and distribution via underground forums remain largely untouched. This means the attack wave following a seizure is often only interrupted briefly before follow-up activity resumes under new infrastructure.

For CISOs, this means that takedown announcements alone are no reason to consider the threat posed by MFA-bypassing phishing kits as defused. Security teams should continue to rely on detection mechanisms that do not depend solely on known domains or IOC lists, but instead account for behavioral patterns such as unusual session takeovers or anomalies in authentication flows. In addition, the combination of phishing-resistant authentication methods, such as FIDO2/WebAuthn, and continuous monitoring remains the most effective protection against PhaaS attacks, which are conceptually designed to circumvent classic MFA methods.


Source: www.security-insider.de · Published August 4, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: