TLDR Coinbase, Microsoft, and Europol took down Tycoon 2FA, one of the world’s largest phishing-as-a-service platforms Tycoon 2FA accounted for 62% of all phishingTLDR Coinbase, Microsoft, and Europol took down Tycoon 2FA, one of the world’s largest phishing-as-a-service platforms Tycoon 2FA accounted for 62% of all phishing

Coinbase, Microsoft and Europol Dismantle Tycoon 2FA Crypto Phishing Network

2026/03/05 16:29
3 min read
For feedback or concerns regarding this content, please contact us at [email protected]

TLDR

  • Coinbase, Microsoft, and Europol took down Tycoon 2FA, one of the world’s largest phishing-as-a-service platforms
  • Tycoon 2FA accounted for 62% of all phishing attempts blocked by Microsoft by mid-2025, including 30 million emails in one month
  • The platform bypassed multi-factor authentication by stealing session cookies and tokens
  • Coinbase traced blockchain transactions to help identify the platform’s alleged administrator and buyers
  • Phishing losses dropped 83% in 2025, but attackers are using increasingly advanced techniques

A coalition of tech companies and law enforcement took down one of the world’s biggest phishing platforms this week. Coinbase, Microsoft, and Europol announced Wednesday they dismantled the core infrastructure of Tycoon 2FA.

Tycoon 2FA was a phishing-as-a-service platform. It sold subscription-based toolkits that let criminals steal login credentials and bypass multi-factor authentication (MFA).

The platform has been active since at least 2023. By mid-2025, it accounted for 62% of all phishing attempts blocked by Microsoft.

At its peak, Tycoon generated tens of millions of phishing emails every month. It facilitated unauthorized access to nearly 100,000 organizations globally, including schools, hospitals, and public institutions.

Microsoft blocked 330 domains tied to the platform. Law enforcement also seized additional key infrastructure as part of the operation.

How the Platform Bypassed Multi-Factor Authentication

Tycoon’s toolkit included spoofed landing pages designed to look like legitimate websites. When a user logged in, the platform captured their session cookies and tokens.

A session token is proof that a user has already authenticated. If a hacker steals that token, they can use it to access the account without triggering MFA prompts again.

By lowering the technical barrier, Tycoon allowed criminals with limited skills to run sophisticated campaigns. Industries from healthcare to education were affected, resulting in stolen data, rerouted invoices, and disruptions to patient care.

Coinbase’s Role in Tracing Crypto Transactions

Coinbase played a key role by tracing blockchain transactions used to fund the platform. That financial trail helped law enforcement identify the alleged administrator and several buyers.

Coinbase also said it is actively working to identify people who purchased Tycoon’s tools and will continue supporting law enforcement efforts.

Phishing was flagged as the second-largest threat to crypto users in 2025 by blockchain security firm CertiK, costing investors $722 million across 248 incidents.

Overall phishing losses dropped 83% in 2025 compared to the prior year. However, attackers have continued developing advanced techniques, including exploits tied to EIP-7702 and Permit2 signature-based attacks.

A spokesperson from blockchain security firm PeckShield told Cointelegraph that phishing remains a “persistent threat” in 2026.

The post Coinbase, Microsoft and Europol Dismantle Tycoon 2FA Crypto Phishing Network appeared first on CoinCentral.

Market Opportunity
Dino Tycoon Logo
Dino Tycoon Price(TYCOON)
$0.002159
$0.002159$0.002159
-6.53%
USD
Dino Tycoon (TYCOON) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact [email protected] for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

World Gold Council’s Pivotal Framework Promises Unprecedented Market Trust

World Gold Council’s Pivotal Framework Promises Unprecedented Market Trust

The post World Gold Council’s Pivotal Framework Promises Unprecedented Market Trust appeared on BitcoinEthereumNews.com. Tokenized Gold Revolution: World Gold Council
Share
BitcoinEthereumNews2026/03/20 03:58
Aave DAO to Shut Down 50% of L2s While Doubling Down on GHO

Aave DAO to Shut Down 50% of L2s While Doubling Down on GHO

The post Aave DAO to Shut Down 50% of L2s While Doubling Down on GHO appeared on BitcoinEthereumNews.com. Aave DAO is gearing up for a significant overhaul by shutting down over 50% of underperforming L2 instances. It is also restructuring its governance framework and deploying over $100 million to boost GHO. This could be a pivotal moment that propels Aave back to the forefront of on-chain lending or sparks unprecedented controversy within the DeFi community. Sponsored Sponsored ACI Proposes Shutting Down 50% of L2s The “State of the Union” report by the Aave Chan Initiative (ACI) paints a candid picture. After a turbulent period in the DeFi market and internal challenges, Aave (AAVE) now leads in key metrics: TVL, revenue, market share, and borrowing volume. Aave’s annual revenue of $130 million surpasses the combined cash reserves of its competitors. Tokenomics improvements and the AAVE token buyback program have also contributed to the ecosystem’s growth. Aave global metrics. Source: Aave However, the ACI’s report also highlights several pain points. First, regarding the Layer-2 (L2) strategy. While Aave’s L2 strategy was once a key driver of success, it is no longer fit for purpose. Over half of Aave’s instances on L2s and alt-L1s are not economically viable. Based on year-to-date data, over 86.6% of Aave’s revenue comes from the mainnet, indicating that everything else is a side quest. On this basis, ACI proposes closing underperforming networks. The DAO should invest in key networks with significant differentiators. Second, ACI is pushing for a complete overhaul of the “friendly fork” framework, as most have been unimpressive regarding TVL and revenue. In some cases, attackers have exploited them to Aave’s detriment, as seen with Spark. Sponsored Sponsored “The friendly fork model had a good intention but bad execution where the DAO was too friendly towards these forks, allowing the DAO only little upside,” the report states. Third, the instance model, once a smart…
Share
BitcoinEthereumNews2025/09/18 02:28
Shiba Inu Price Prediction 2026: SHIB Fights to Reclaim Its Glory While Pepeto Offers the 150x Early Window That SHIB Already Closed

Shiba Inu Price Prediction 2026: SHIB Fights to Reclaim Its Glory While Pepeto Offers the 150x Early Window That SHIB Already Closed

A truck driver put $650 into Shiba Inu in 2020 and quit his job after his bag grew to $1.7 million. Two brothers invested $7,900 during the COVID lockdowns and
Share
Blockonomi2026/03/20 04:32