Coinbase, Microsoft, Europol, and others jointly shut down Tycoon 2FA phishing site

Source Cryptopolitan

Coinbase announced Wednesday it was part of a coordinated effort to take down phishing-as-a-service giant Tycoon 2FA. The action was led by Microsoft, Europol, and ten other partners.

Tycoon was responsible for tens of millions of fraudulent emails reaching over 500,000 organizations each month across the world, according to the report

As a phishing-as-a-service, Tycoon enabled thousands of threat actors to steal credentials at scale and bypass multi-factor authentication by capturing session cookies/tokens. Having such access meant that attackers could exploit users’ accounts without triggering authentication prompts.

Campaigns from Tycoon primarily targeted email and online service accounts, especially from Microsoft 365, Outlook, and Gmail.

Microsoft, Coinbase, and others take down Tycoon 2FA

The site had up to 2,000 users and operated more than 24,000 domains since its launch in August 2023. 

Microsoft said it seized 330 active domains powering the site and its control panels, under a court order from the U.S. District Court for the Southern District of New York. Together, they also identified the primary developer to be Saad Fridi, based in Pakistan. 

Coinbase said it helped trace the crypto payments that funded Tycoon’s operation and supported the civil action to seize the domains. The exchange said efforts are still ongoing with law enforcement to pursue the people who bought and used the Tycoon phishing service.

“This was not a single phishing campaign. It was an industrialized service built to make MFA bypass accessible to thousands of criminals,” said Robert McArdle, Director for Cybercrime Research at TrendAITM, one of the partners. 

Crypto losses to phishing attack hit $83 million

Earlier in January, Chainalysis reported that crypto scams are becoming increasingly industrialized with the rise of phishing-as-a-service and other tools. 

Some of the phishing kits are bought for under $500, but at scale, they can lead to millions of dollars in losses.

“This modular, service-based approach is a force multiplier and allows even technically unsophisticated criminals to execute sophisticated phishing campaigns, substantially lowering the barrier to entry for cryptocurrency fraud,” Chainalysis wrote.

Up to 106,106 victims lost their cryptocurrency to phishing attacks last year, though the figure was a lot lower than the year before. According to Scam Sniffer, crypto users lost $83.85 million, marking an 83% decline from the compared to $494 million recorded in 2024.

Coinbase, Microsoft take down phishing site Tycoon 2FA, seize 330 domains
Quarterly phishing losses. Source: Scam Sniffer

Scam Sniffer found that phishing losses correlate with market activities. More losses were recorded in Q3, totaling $31 million, when ETH saw its strongest rally for the year, Cryptopolitan reported.

The smartest crypto minds already read our newsletter. Want in? Join them.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Chainlink connects $5B cbBTC to Monad via CCIP, expanding cross-chain Bitcoin liquidity accessChainlink expanded its cross-chain infrastructure after integrating Coinbase’s wrapped Bitcoin token, cbBTC, with the Monad blockchain through its Cross-Chain Interoperability Protocol (CCIP).  The connection enables more than $5 billion in cbBTC supply to be accessible to decentralized finance (DeFi) applications operating on Monad. The move strengthens Chainlink’s position in cross-chain and institutional infrastructure. cbBTC goes […]
Author  Cryptopolitan
20 hours ago
Chainlink expanded its cross-chain infrastructure after integrating Coinbase’s wrapped Bitcoin token, cbBTC, with the Monad blockchain through its Cross-Chain Interoperability Protocol (CCIP).  The connection enables more than $5 billion in cbBTC supply to be accessible to decentralized finance (DeFi) applications operating on Monad. The move strengthens Chainlink’s position in cross-chain and institutional infrastructure. cbBTC goes […]
placeholder
U.S. set to get crypto perpetual futures as CFTC speeds ahead of congressThe Commodity Futures Trading Commission (CFTC) plans to allow U.S. crypto perpetual futures within weeks.
Author  Cryptopolitan
20 hours ago
The Commodity Futures Trading Commission (CFTC) plans to allow U.S. crypto perpetual futures within weeks.
placeholder
How Trump’s Escalation With Iran Could Become the Catalyst for Declining Political SupportIsrael and the United States have launched a joint attack on Iran, one that has an unclear expiry date and that has already caused reverberations across the rest of the Middle East. Though Israel’s in
Author  Beincrypto
20 hours ago
Israel and the United States have launched a joint attack on Iran, one that has an unclear expiry date and that has already caused reverberations across the rest of the Middle East. Though Israel’s in
placeholder
Bitcoin’s Second-Largest Corporate Holder Just Changed the Rules: Is MicroStrategy Next?MARA Holdings has formally rewritten its Bitcoin playbook, expanding its treasury policy to permit sales of Bitcoin held directly on its balance sheet.It raises questions about whether Strategy (Micro
Author  Beincrypto
20 hours ago
MARA Holdings has formally rewritten its Bitcoin playbook, expanding its treasury policy to permit sales of Bitcoin held directly on its balance sheet.It raises questions about whether Strategy (Micro
placeholder
Solana Sell Pressure Builds as Exchange Inflows Rise—$77 Is the LineSolana (SOL) has been facing a period of consolidation, with its price fluctuating between $87 and $77 in recent weeks. However, recent developments in the market suggest that the cryptocurrency could
Author  Beincrypto
20 hours ago
Solana (SOL) has been facing a period of consolidation, with its price fluctuating between $87 and $77 in recent weeks. However, recent developments in the market suggest that the cryptocurrency could
goTop
quote