Tycoon 2FA’s disruption matters less as a takedown than as a shift in tradecraft. When operators lose infrastructure, they do not disappear; they move to easier account-takeover methods that use legitimate login flows instead of obvious fake pages, which makes 2FA feel safer than it is.
Barracuda says a coordinated law enforcement action knocked out 330 active Tycoon domains and cut monthly output from more than 9 million attacks to just over 2 million. The same reporting says many operators are scattering to other phishing services, and some are adopting device-code phishing, which abuses a service’s new-device login flow to capture access.
The forward risk is broader account takeover with less user suspicion. Device-code phishing lowers the barrier for phishers because the victim is pushed through a real authentication flow, so standard “spot the fake login page” training misses the attack path.