Europol and Microsoft Disrupt Major Phishing-as-a-Service Platform, Tycoon2FA
A coordinated international effort led by Europol and Microsoft has dismantled Tycoon2FA, a significant phishing-as-a-service (PhaaS) platform that facilitated the widespread theft of credentials and access to secure accounts. The operation, which involved law enforcement agencies from Belgium, Latvia, Lithuania, Portugal, Poland, Spain, and the United Kingdom, targeted a platform that allowed cybercriminals to rent phishing tools, including those capable of bypassing multi-factor authentication (MFA).
What Was Tycoon2FA?
Tycoon2FA, also known as Tycoon 2FA, operated as a “cybercriminal supermarkt” where individuals could acquire ready-made phishing tools without requiring extensive technical expertise [VRT]. The platform provided a dashboard where users could “hire” phishing emails, fake websites, and software designed to circumvent security measures like two-factor authentication. Microsoft likened the service to a meal kit delivery, providing all the necessary “ingredients” and instructions for launching sophisticated phishing campaigns [VRT].
Scale of the Operation
The platform was highly active, with Microsoft estimating that it facilitated the sending of over 30 million phishing messages in November 2025 alone [Brussels Times]. Tycoon2FA targeted more than 500,000 organizations globally [CyberSecureFox]. During the disruption, over 330 domains, including phishing pages and control panels, were taken down [Europol].
Impact in Belgium
Belgium was significantly affected by Tycoon2FA, with over 500 victims identified, including both businesses and private individuals [VRT].
Collaboration and Technical Disruption
The dismantling of Tycoon2FA was a collaborative effort between law enforcement and the private sector. Europol coordinated the operation through its European Cybercrime Centre (EC3), while Microsoft provided crucial technical support, leveraging its incident response teams and a network of private partners. Initial intelligence regarding Tycoon2FA’s infrastructure came from Trend Micro [CyberSecureFox]. Other organizations involved included Cloudflare, Coinbase, Intel471, Proofpoint, Shadowserver Foundation, SpyCloud, eSentire, and Resecurity.
Looking Ahead
This operation highlights the increasing importance of public-private partnerships in combating cybercrime. The success of disrupting Tycoon2FA demonstrates the effectiveness of data sharing, automated exchange of threat indicators, and cross-border legal collaboration in tackling large-scale phishing operations. As phishing-as-a-service platforms continue to evolve, continued vigilance and cooperation will be essential to protecting individuals and organizations from cyber threats.