Coinbase, Microsoft and Europol Dismantle Tycoon 2FA Phishing Network, Seize 330 Domains

Coinbase, Microsoft and Europol Dismantle Tycoon 2FA Phishing Network, Seize 330 Domains

N
News Editor 01
2026-07-23 01:00:14
International operation took down Tycoon 2FA, a phishing-as-a-service platform behind 62% of Microsoft-blocked phishing attempts affecting nearly 100,000 organizations. Coinbase traced crypto payments to identify a suspect; Microsoft led technical takedown.
CoinbaseMicrosoftEuropolPhishing-as-a-ServiceMFA bypass

A coordinated international operation involving Coinbase, Microsoft, and Europol has dismantled Tycoon 2FA, a large-scale phishing-as-a-service platform that allowed cybercriminals to bypass multi-factor authentication (MFA). Authorities seized 330 domains used for phishing pages and administrative control panels, cutting off the attackers' infrastructure.

Platform Scale: Tens of Millions of Phishing Emails Monthly

Tycoon 2FA operated as a subscription-based toolkit enabling real-time capture of login credentials and authentication data. It intercepted live sessions to collect session cookies or tokens, letting attackers bypass MFA without triggering extra security checks. Active since at least August 2023, the service grew into one of the world's largest phishing operations. At its peak, it generated tens of millions of phishing emails each month and facilitated unauthorized access to nearly 100,000 organizations globally, including schools, hospitals, and public institutions. By mid-2025, Tycoon 2FA accounted for roughly 62% of all phishing attempts blocked by Microsoft's systems.

Public-Private Investigation: From Intel to Domain Seizures

The operation stemmed from intelligence initially shared by cybersecurity firm Trend Micro. Europol's European Cybercrime Centre coordinated law enforcement agencies from Latvia, Lithuania, Portugal, Poland, Spain, and the UK's National Crime Agency to seize infrastructure linked to the network. Technical disruption was led by Microsoft with assistance from Cloudflare, Proofpoint, and the Shadowserver Foundation. Microsoft later filed a civil action that resulted in court-authorized domain seizures, taking Tycoon's control panels offline.

Coinbase Traced Crypto Payments, Identified Suspected Admin

Coinbase's global intelligence team played a key role in tracking the financial flow behind the operation. Analysts traced cryptocurrency payments used to fund Tycoon 2FA's subscription service, helping investigators map connections between the platform's operator and its customers. Coinbase said its analysis contributed to identifying the suspected administrator, Saad Fridi, believed to be based in Pakistan. No arrests have been announced, but financial tracing is highlighted as a core element of the takedown.

While the disruption removes a major tool for credential theft, authorities warn that similar phishing-as-a-service platforms continue to emerge, lowering entry barriers for cybercriminals. The case underscores growing collaboration between tech firms, crypto analytics teams, and law enforcement to combat cross-border cybercrime networks.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
700

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.