A coordinated international operation involving Coinbase, Microsoft, and Europol has dismantled Tycoon 2FA, a large-scale phishing-as-a-service platform that allowed cybercriminals to bypass multi-factor authentication (MFA). Authorities seized 330 domains used for phishing pages and administrative control panels, cutting off the attackers' infrastructure.
Platform Scale: Tens of Millions of Phishing Emails Monthly
Tycoon 2FA operated as a subscription-based toolkit enabling real-time capture of login credentials and authentication data. It intercepted live sessions to collect session cookies or tokens, letting attackers bypass MFA without triggering extra security checks. Active since at least August 2023, the service grew into one of the world's largest phishing operations. At its peak, it generated tens of millions of phishing emails each month and facilitated unauthorized access to nearly 100,000 organizations globally, including schools, hospitals, and public institutions. By mid-2025, Tycoon 2FA accounted for roughly 62% of all phishing attempts blocked by Microsoft's systems.
Public-Private Investigation: From Intel to Domain Seizures
The operation stemmed from intelligence initially shared by cybersecurity firm Trend Micro. Europol's European Cybercrime Centre coordinated law enforcement agencies from Latvia, Lithuania, Portugal, Poland, Spain, and the UK's National Crime Agency to seize infrastructure linked to the network. Technical disruption was led by Microsoft with assistance from Cloudflare, Proofpoint, and the Shadowserver Foundation. Microsoft later filed a civil action that resulted in court-authorized domain seizures, taking Tycoon's control panels offline.
Coinbase Traced Crypto Payments, Identified Suspected Admin
Coinbase's global intelligence team played a key role in tracking the financial flow behind the operation. Analysts traced cryptocurrency payments used to fund Tycoon 2FA's subscription service, helping investigators map connections between the platform's operator and its customers. Coinbase said its analysis contributed to identifying the suspected administrator, Saad Fridi, believed to be based in Pakistan. No arrests have been announced, but financial tracing is highlighted as a core element of the takedown.
While the disruption removes a major tool for credential theft, authorities warn that similar phishing-as-a-service platforms continue to emerge, lowering entry barriers for cybercriminals. The case underscores growing collaboration between tech firms, crypto analytics teams, and law enforcement to combat cross-border cybercrime networks.

