MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Major Phishing Network Tycoon 2FA Shut Down by Coinbase, Microsoft, and Europol – Blockonomi
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$71,574.00-1.49%
  • ethereumEthereum(ETH)$2,212.95-0.94%
  • tetherTether(USDT)$1.00-0.01%
  • rippleXRP(XRP)$1.33-1.36%
  • binancecoinBNB(BNB)$593.54-2.06%
  • usd-coinUSDC(USDC)$1.000.02%
  • solanaSolana(SOL)$82.34-2.20%
  • tronTRON(TRX)$0.3208830.70%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.041.81%
  • dogecoinDogecoin(DOGE)$0.091212-1.66%
Blockchain Security

Major Phishing Network Tycoon 2FA Shut Down by Coinbase, Microsoft, and Europol – Blockonomi

Last updated: March 5, 2026 7:35 pm
Published: 1 month ago
Share

Despite an 83% decline in phishing-related losses during 2025, cybercriminals continue deploying more sophisticated attack methods

This week witnessed a significant victory in the fight against cybercrime as a partnership between major technology firms and international law enforcement successfully dismantled a sprawling phishing operation. On Wednesday, Coinbase, Microsoft, and Europol jointly announced they had taken down the primary infrastructure supporting Tycoon 2FA.

Tycoon 2FA operated as a phishing-as-a-service enterprise, offering criminals subscription-based access to advanced toolkits designed to harvest login credentials and circumvent multi-factor authentication protections.

The criminal platform had been operational since 2023 at minimum. By the midpoint of 2025, Tycoon 2FA was responsible for an astounding 62% of all phishing attempts that Microsoft successfully intercepted.

During its operational peak, the platform generated tens of millions of malicious emails monthly. The service enabled unauthorized intrusions into approximately 100,000 organizations across the globe, affecting diverse sectors including educational institutions, healthcare facilities, and government agencies.

Microsoft successfully blocked 330 domain names associated with the operation. Simultaneously, law enforcement agencies confiscated additional critical infrastructure components during the coordinated takedown.

The Tycoon platform provided criminals with sophisticated phishing kits featuring convincing replica pages that mimicked authentic websites. When unsuspecting users entered their credentials, the system captured their session cookies and authentication tokens.

Session tokens serve as digital proof that a user has completed the authentication process. Once a cybercriminal obtains these tokens, they can hijack the authenticated session without triggering additional MFA verification requests.

“This powerful combination — convincing fake pages combined with session-token interception — transforms phishing into an effective gateway for more serious criminal activities including account takeovers, business email compromise schemes, and invoice fraud,” Coinbase explained.

By eliminating technical barriers to entry, Tycoon enabled even relatively unskilled criminals to execute advanced phishing campaigns. The platform’s reach extended across multiple sectors from medical services to academic institutions, resulting in compromised data, fraudulent payment redirections, and interruptions to critical services like patient care.

Coinbase contributed critical investigative support by analyzing blockchain transaction records associated with the platform’s financial operations. This digital money trail provided investigators with crucial intelligence that helped identify the suspected platform administrator and multiple customers.

“Dismantling Tycoon’s primary infrastructure eliminates a significant channel for credential theft and compels cybercriminals to restart their operations from scratch, adopt new tools, and accept greater exposure to detection,” Coinbase stated.

The cryptocurrency exchange confirmed it continues working to identify individuals who acquired Tycoon’s criminal tools and remains committed to supporting ongoing law enforcement investigations.

Blockchain security company CertiK identified phishing as the second most significant threat facing cryptocurrency users in 2025, with investors losing $722 million across 248 separate incidents.

While overall phishing-related losses declined by 83% in 2025 compared to the previous year, threat actors have continued evolving their tactics, including exploits leveraging EIP-7702 vulnerabilities and Permit2 signature-based attack vectors.

A representative from blockchain security company PeckShield informed Cointelegraph that phishing continues to represent a “persistent threat” heading into 2026.

Read more on Blockonomi

This news is powered by Blockonomi Blockonomi

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Ether.fi Launches One-Click Vaults With Enso-Powered Cross-Chain Deposits
Crypto Hacks Cost $127M In September, An Encouraging Decline From 22% In August – FinanceFeeds
Little Pepe (LILPEPE) Rockets Past $19,325,000 In Presale With 10 Stages Now Sold Out
Crypto wallets launch defense network after phishers jack $400M
Hypervault Vanishes as $3.6 Million Funneled Through Tornado Cash

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article MEXC Releases February Proof of Reserve Report, BTC Coverage Rises to 267% | Weekly Voice
Next Article WhiteBIT Coin ($WBT) Officially Listed on Kraken Exchange, Highlighting Its Growing Recognition
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d