惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
小众软件
小众软件
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - Franky
Jina AI
Jina AI
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Y
Y Combinator Blog
V
Visual Studio Blog
C
Check Point Blog
阮一峰的网络日志
阮一峰的网络日志
U
Unit 42
量子位
人人都是产品经理
人人都是产品经理
博客园 - 聂微东
M
MIT News - Artificial intelligence
爱范儿
爱范儿
B
Blog RSS Feed
MyScale Blog
MyScale Blog
H
Help Net Security
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
美团技术团队
L
LangChain Blog
D
Docker

Enterprise – Silicon Republic

EU finally gets its hands on Anthropic’s Mythos New Irish dispute body to tackle illegal online content launched Rhysida leaks 5.7TB of sensitive Berlin state data in major hack ‘Keeping OT security up to date is more than patching systems’ HSE fined €645,000 for storing records in decrepit conditions Boston Scientific cyberattack: Cork staff asked to work remotely Report: Only sectors aiding AI adoption sure to grow from it Why connectivity and cybersecurity can't be treated separately French authorities investigating hack of national tax authority Why employee retention is at the heart of the cyber skills gap Levi Strauss corporate data stolen in cyberattack Levi Strauss corporate data stolen in cyberattack How might a system ‘leak secrets’ without being hacked? What is a side-channel attack in cybersecurity? OpenAI agents breach Modal client system after Hugging Face hack OpenAI agents breach Modal client system after Hugging Face hack Report: EMEA businesses not reaping benefits from their AI spend Report: EMEA businesses not reaping benefits from their AI spend Transport for London hackers jailed for five and a half years Transport for London hackers jailed for five and a half years Commission refers Ireland to CJEU for failing to enact cyber rules Commission refers Ireland to CJEU for failing to enact cyber rules Cloudflare to block AI crawlers from ad-supported webpages by default Cloudflare to block AI crawlers from ad-supported webpages by default Google ordered to pay Klarna nearly $2bn in abuse-of-power row Google ordered to pay Klarna nearly $2bn in abuse-of-power row Upcoming iPhone 18 model leaked in Tata Electronics hack New iPhone 18 models reportedly leaked in Tata Electronics hack Data breaches going unreported – Irish compliance survey Data breaches going unreported, says Irish compliance survey
Major phishing operation disrupted in joint Europol action
Suhasini Srinivasaragavan · 2026-03-05 · via Enterprise – Silicon Republic

Tycoon 2FA accounted for around 62pc of all phishing attempts blocked by Microsoft by mid-2025.

A joint cybersecurity operation has disrupted one of the world’s largest phishing-as-a-service platforms, called ‘Tycoon 2FA’ and used to bypass multi-factor authentication (MFA) and hack user accounts.

The operation was coordinated by Europol’s European Cybercrime Centre, while technical disruption was led by Microsoft. Participating industry partners also included Cloudflare, Coinbase, Proofpoint and Esentire, among others.

Japanese cybersecurity firm Trend Micro shared intelligence that allowed the investigation to initiate, Europol noted. Law enforcement authorities from several European countries, including Spain and the UK, also participated.

Tycoon 2FA provided cybercriminals with a subscription-based toolkit that intercepted live authentication sessions to gain unauthorised access to online accounts, including those that were protected by additional security layers.

The platform has been active since at least 2023, according to Europol, and enabled “thousands” of cybercriminals to access email and cloud-based service accounts. Experts determined that the platform generated “tens of millions” of phishing emails each month, attempting to gain access to nearly 100,000 organisations globally, including schools, hospitals and public institutions.

“Campaigns leveraging Tycoon 2FA have appeared across nearly all sectors including education, healthcare, finance, non-profit and government,” said Microsoft.

“Its rise in popularity among cybercriminals likely stemmed from disruptions of other popular phishing services”, it noted.

Tycoon 2FA accounted for around 62pc of all phishing attempts blocked by Microsoft by mid-2025. Its platform enabled threat actors to impersonate trusted brands by copying sign-in pages for services including Microsoft’s own 365 and OneDrive, and Gmail. It also allowed criminals to access sensitive information even after passwords were reset.

Targets were lured through phishing emails containing attachments with svg, pdf, html or docx files, often embedded with QR codes or JavaScript. To evade detection, the platform used techniques such as anti-bot screening, browser fingerprinting and self-hosted Captchas.

The joint industry and law enforcement operation led to the disruption of 330 domains that formed the core infrastructure of the criminal service, including phishing pages and control panels.

However, Microsoft pointed out that Tycoon 2FA illustrates the “evolution of phishing kits in response to rising enterprise defences”. The platform shows how cybercriminals adapt lures, infrastructure and evasion techniques to stay ahead of detection.

Recently, Google and iVerify highlighted the existence of a hacking mechanism, with suspected US origins, now used by bad actors to infiltrate outdated iPhones.

Meanwhile, Amazon last month highlighted how commercial AI is being used by less technically savvy cybercriminals to scale cyberattacks on enterprises.

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.