A joint effort between law enforcement agencies and tech companies, including Coinbase and Microsoft, has dismantled the core infrastructure of Tycoon 2FA – a phishing-as-a-service platform that provides tools to bypass multi-factor authentication (MFA). Europol stated that Microsoft has blocked 330 related domains, while authorities seized additional key infrastructure. Coinbase assisted in tracing blockchain transactions funding Tycoon, helping identify administrators and service buyers.
Tycoon uses fake websites and session token theft to bypass MFA, enabling account hijacking and financial fraud. According to Microsoft, by mid-2025, Tycoon accounted for 62% of blocked phishing incidents, with over 30 million emails in one month. CertiK’s report shows phishing caused $722 million in damages in 2025, remaining a major threat to cryptocurrency investors.
