Tycoon2FA dismantled: How TrendAI research supported the Europol-led takedown

Posted: 12th Mar 2026

Have you heard about Tycoon2FA?

Linked to more than 96,000 victims globally, this phishing-as-a-service platform enabled attackers to bypass multi-factor authentication (MFA) using adversary-in-the-middle (AiTM) proxying, allowing them to intercept login sessions and capture valid credentials in real time.

Tycoon2FA has recently been dismantled, and our threat researchers at TrendAI™, a business unit of Trend Micro, played a key role in the global disruption of the platform. Here is how and what you should know.

View Full Article

Related Articles

Popular Articles

AI doesn't fix bad data hygiene - it just surfaces it faster and at scale. We explain what that mean...
As compute moves closer to the user and the edge becomes the epicenter of business innovation, physi...
As the leaders of the Five Eyes cyber security agencies, we are united in our call to action: the ev...
Something shifted in late 2025 that I don't think our industry has fully reckoned with yet.  W...