{"meta":{"database":"Global Social Engineering Impact Database","url":"https://global-social-engineering-impact-da.vercel.app","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","generated":"2026-08-29T09:20:11.836Z","total":1,"returned":1,"limit":50,"offset":0,"next":null,"note":"Read loss_kind before summing loss_usd: only direct_loss and ransom_paid are comparable. Entries with entry_type \"benchmark\" are aggregate agency statistics and overlap with everything else by construction."},"results":[{"slug":"2026-tycoon2fa-phishing-as-a-service-disrupted-after-reaching-500-000-orgs-a","title":"Tycoon2FA phishing-as-a-service disrupted after reaching 500,000 orgs a month","date":"2026-03","date_precision":"month","year":2026,"victim_org":"Organisations across education, healthcare, finance, nonprofit and government","sector":"Other","country":"Global","primary_vector":"Credential Phishing Portal","secondary_vectors":["Spear Phishing (Email)","QR Code Phishing"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Credential Theft","Data Breach","Attempt Blocked"],"loss_usd":null,"loss_kind":null,"loss_note":"","records_affected":null,"threat_actor":"Tycoon2FA phishing-as-a-service operators","summary":"Microsoft's Digital Crimes Unit, working with Europol, Trend Micro and industry partners, disrupted the Tycoon2FA phishing-as-a-service platform in March 2026. By early 2026 the service was pushing tens of millions of phishing messages reaching more than 500,000 organisations a month worldwide. Subscriptions ran from $120 for ten days to $350 a month and included ready-made Microsoft 365, Outlook, SharePoint, OneDrive and Gmail sign-in templates.","how_it_worked":"Tycoon2FA industrialised adversary-in-the-middle credential theft for buyers with no technical skill. A subscriber picked a template and sent lures; when a recipient entered their password on the fake sign-in page, the platform relayed it live to the real Microsoft or Google service and captured the returned session cookie along with whatever MFA the user completed. That defeated SMS codes, one-time passcodes and push approvals alike, because the victim genuinely authenticated, just into the attacker's session. Domains were rotated every 24 to 72 hours on cheap generic TLDs using readable subdomains such as cloud, desktop and sharepoint.","lessons":"Only origin-bound credentials such as FIDO2 passkeys break the relay; conditional access requiring a compliant managed device makes a stolen cookie useless from attacker infrastructure.","confidence":"Confirmed","sources":[{"title":"Inside Tycoon2FA: How a leading AiTM phishing kit operated at scale","url":"https://www.microsoft.com/en-us/security/blog/2026/03/04/inside-tycoon2fa-how-a-leading-aitm-phishing-kit-operated-at-scale/","publisher":"Microsoft Security Blog"},{"title":"Europol, Microsoft, TrendAI and Collaborators Halt Tycoon 2FA Operations","url":"https://www.trendmicro.com/en_us/research/26/c/tycoon2fa-takedown.html","publisher":"Trend Micro"}],"entry_type":"campaign","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-tycoon2fa-phishing-as-a-service-disrupted-after-reaching-500-000-orgs-a"}]}