{"id":8870,"date":"2026-07-24T10:23:03","date_gmt":"2026-07-24T10:23:03","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=8870"},"modified":"2026-07-24T10:23:03","modified_gmt":"2026-07-24T10:23:03","slug":"tycoon2fa-takedown-reshapes-the-phishing-landscape","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=8870","title":{"rendered":"Tycoon2FA takedown reshapes the phishing landscape"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Traditional phishing techniques are in decline as a result of the <a href=\"https:\/\/www.csoonline.com\/article\/4140890\/microsoft-leads-takedown-of-tycoon2fa-phishing-service-infrastructure.html\">disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform<\/a>, Microsoft said in a new report, \u201cEmail threat landscape: Q2 2026 trends and insights\u201d.<\/p>\n<p class=\"wp-block-paragraph\">\u201cPhishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March highs,\u201d the company wrote in <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/07\/23\/email-threat-landscape-q2-2026-trends-and-insights\/\">the report<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">The takedown reduced activity across multiple phishing categories, forcing attackers to shift to newer delivery methods.<\/p>\n<p class=\"wp-block-paragraph\">Riding this shift in were a few notable phishing campaigns, including an automated <a href=\"https:\/\/www.csoonline.com\/article\/575559\/business-email-compromise-scams-take-new-dimension-with-multi-stage-attacks.html\">business email compromise<\/a> (BEC) campaign that reached 42,000 organizations in under three hours, and a multi-stage phishing campaign that used nested email (EML) files, calendar invitations, and a Microsoft authentication redirect to deliver malware.<\/p>\n<p class=\"wp-block-paragraph\">To counter phishing attacks, Microsoft recommends blocking emails containing known bad URLs\/ subject fields, enabling password-less authentication methods, or moving to <a href=\"https:\/\/www.csoonline.com\/article\/4176814\/security-experts-caution-mfa-alone-can-no-longer-stop-threat-actors.html\">MFA<\/a> for accounts that still require passwords.<\/p>\n<h2 class=\"wp-block-heading\">Tycoon2FA disruption sent attackers exploring<\/h2>\n<p class=\"wp-block-paragraph\">The take-down of <a href=\"https:\/\/www.csoonline.com\/article\/4100393\/hybrid-2fa-phishing-kits-are-making-attacks-harder-to-detect.html\">Tycoon2FA<\/a> forced its operators to abandon portions of their infrastructure and rework hosting, domain registrations, and delivery mechanisms.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAfter falling 15% in March and another 22% in April, Tycoon2FA-linked phishing volume dropped 74% in May to just 1.5 million messages, then fell another 20% in June to 1.2 million, by far the lowest monthly volumes observed in at least a year,\u201d Microsoft said.<\/p>\n<p class=\"wp-block-paragraph\">The decline extended to QR Code <a href=\"https:\/\/www.csoonline.com\/article\/3557585\/attackers-are-using-qr-codes-sneakily-crafted-in-ascii-and-blob-urls-in-phishing-emails.html\">lures<\/a> and fake CAPTCHA <a href=\"https:\/\/www.csoonline.com\/article\/3829416\/fake-captcha-attacks-are-increasing-say-experts.html\">pages<\/a>, two phishing techniques in which Tycoon2FA accounted for 12% and 14% of industry activity in June, respectively. This indicated that the platform\u2019s customer base had not been able to migrate to a replacement infrastructure.<\/p>\n<p class=\"wp-block-paragraph\">But cutting off one head of the hacker hydra only gave rise to new tactics elsewhere.<\/p>\n<p class=\"wp-block-paragraph\">The adaptation came in the form of using Microsoft <a href=\"https:\/\/www.csoonline.com\/article\/4160858\/attackers-abuse-microsoft-teams-to-impersonate-the-it-helpdesk-in-a-new-enterprise-intrusion-playbook.html\">Teams as a social engineering channel<\/a>. Attackers established conversations to build trust before attempting credential theft or delivering malicious payloads. \u201cTeams-based phishing volume climbed steadily throughout Q2, with the average number of detected attacks rising 19% from March to April, holding roughly flat into May (+1%), then increasing another 10% into June,\u201d Microsoft said.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft also observed a highly automated BEC campaign that reached over 67,000 users using scripted emails, Amazon Simple Email Service (SES), and engagement tracking, alongside a separate phishing campaign targeting 107,000 users that abused Microsoft\u2019s authentication flow and trusted cloud services, including Teams archive recording and ICS calendar invite, to disguise malware delivery behind legitimate infrastructure.<\/p>\n<h2 class=\"wp-block-heading\">Phishing changes but the defense doesn\u2019t<\/h2>\n<p class=\"wp-block-paragraph\">While QR Code and Captcha-based phishing attacks dropped significantly in the second quarter, business email compromise (BEC) charted jumped 121% between March and April, before dropping down again in May.<\/p>\n<p class=\"wp-block-paragraph\">QR Code phishing represented 8.3 million attacks in June 2026, down from a peak of 18.7 million in March. Similarly, Captcha-gated phishing fell from 12 million attacks in March to 2.2 million in June.<\/p>\n<p class=\"wp-block-paragraph\">BEC attacks hit 9 million in March, falling to 3.9 million in June.<\/p>\n<p class=\"wp-block-paragraph\">But even as these phishing classics lost momentum and newer techniques emerged, Microsoft\u2019s defensive advice remained rooted in the basics. It noted organizations should complement email filtering with phishing-resistant authentication such as passkeys and phishing-resistant <a href=\"https:\/\/www.csoonline.com\/article\/3535222\/mfa-adoption-is-catching-up-but-is-not-quite-there.html\">MFA<\/a> to reduce the effectiveness of credential theft campaigns.<\/p>\n<p class=\"wp-block-paragraph\">The company also recommended strengthening Exchange Online Protection and Microsoft Defender for Office 365 with capabilities such as Safe links and Zero-hour Auto Purge (ZAP), in which malicious emails already delivered to mailboxes are removed before they are read, alongside enforcing password-less authentication methods like Windows Hello, <a href=\"https:\/\/www.csoonline.com\/article\/4040128\/fido-undermined.html\">FIDO <\/a>keys, and Microsoft Authenticator.<\/p>\n<p class=\"wp-block-paragraph\">Microsoft concluded its report with a list of indicators of compromise (IoCs) from the threats observed in the quarter to support detection efforts.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Traditional phishing techniques are in decline as a result of the disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform, Microsoft said in a new report, \u201cEmail threat landscape: Q2 2026 trends and insights\u201d. \u201cPhishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":8871,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-8870","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8870"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8870"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8870\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/8871"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8870"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8870"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8870"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}