Find notable cyber news and cases, enriched with sources, timelines, and signals.

Tycoon 2FA phishing kit activity at enterprise scale

Malware Activity
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

The Tycoon 2FA phishing kit is being used at scale to relay MFA and steal enterprise sessions, putting Microsoft 365 and Gmail users at risk. More than 64,000 attacks have already been tracked this year. The kit captures session cookies and proxies login flows directly to Microsoft or Google. That makes a single successful phish capable of enabling broad enterprise compromise.

Related Happenings

Jalisco and OmegaLord Microsoft 365 phishing kits

Malware Activity
H score27 First: 14.07.2026 15:49 Last: 14.07.2026 15:49 Sources 1

About this happening: The Jalisco and OmegaLord phishing kits were discovered targeting Microsoft 365 accounts with methods that bypass MFA, increasing the risk of credential theft and...

GPPStorm Google Partners enrollment phishing campaign

Campaign
H score33 First: 13.07.2026 16:03 Last: 13.07.2026 16:03 Sources 1

About this happening: GPPStorm is a phishing campaign that uses bogus Google Partners and Google Premier Partner enrollment workflows to push recipients to a fake Google sign-in page and st...

Microsoft Entra OAuth Client ID spoofing campaign

Campaign
H score58 First: 13.07.2026 16:00 Last: 13.07.2026 16:00 Sources 1

About this happening: A Microsoft Entra ID targeting campaign is using OAuth Client ID spoofing to evade Entra sign-in logs and gain stealthy access to cloud services, increasing the chance...

Forg365-ForgCookie alliance reshapes ransomware ecosystem operations

Threat Actor Meta
H score37 First: 09.07.2026 17:39 Last: 09.07.2026 17:39 Sources 1

About this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...

O-UNC-066 / Pink Microsoft Entra passkey vishing campaign

Campaign
H score37 First: 08.07.2026 19:47 Last: 08.07.2026 19:47 Sources 1

About this happening: The O-UNC-066 / Pink campaign is a voice-based vishing operation that targets Microsoft 365 users with fake security requests that push them to enroll a new Entra pa...

Timeline

  1. 18.11.2025 17:01 2 articles · 7mo ago

    Tycoon 2FA is described as a large-scale MFA relay phishing kit

    Initial Disclosure

    Tycoon 2FA is described as a turnkey Phishing as a Service kit that has enabled over 64,000 attacks this year, often against Microsoft 365 and Gmail, by relaying MFA in real time, capturing credentials and session cookies, and giving operators full session access that can extend into SharePoint, OneDrive, email, Teams, HR systems, and finance systems.

    Show sources