Threats · 150 days ago
Tycoon 2FA’s disruption matters less as a takedown than as a shift in tradecraft. When operators lose infrastructure, they do not disappear; they move to easier account-takeover methods that use legitimate login flows instead of obvious fake pages, which makes 2FA feel safer than it is.
Barracuda says a coordinated law enforcement action knocked out 330 active Tycoon domains and cut monthly output from more than 9 million attacks to just over 2 million. The same reporting says many operators are scattering to other phishing services, and some are adopting device-code phishing, which abuses a service’s new-device login flow to capture access.
The forward risk is broader account takeover with less user suspicion. Device-code phishing lowers the barrier for phishers because the victim is pushed through a real authentication flow, so standard “spot the fake login page” training misses the attack path.
2 sources covering this story
Tycoon 2FA Loses Phishing Kit Crown Amid Surge in Attacks
Threat actors are reusing Tycoon 2FA tools across other phishing kits following the platform’s disruption.
Tycoon 2FA Phishers Scatter, Adopt Device Code Phishing
In embracing device code phishing, attackers trick victims into handing over account access by using a service's legitimate new-device login flow.
Part of the PlainSec briefing for 2026-04-18