Cryptopolitan
April 3, 2026 8:02 PM UTC

Coinbase, Microsoft, Europol, and others jointly shut down Tycoon 2FA phishing site

Coinbase announced Wednesday it was part of a coordinated effort to take down phishing-as-a-service giant Tycoon 2FA. The action was led by Microsoft, Europol, and ten other partners. Tycoon was responsible for tens of millions of fraudulent emails reaching over 500,000 organizations each month across the world, according to the report . As a phishing-as-a-service, Tycoon enabled thousands of threat actors to steal credentials at scale and bypass multi-factor authentication by capturing session cookies/tokens. Having such access meant that attackers could exploit users’ accounts without triggering authentication prompts. Campaigns from Tycoon primarily targeted email and online service accounts, especially from Microsoft 365, Outlook, and Gmail. Microsoft, Coinbase, and others take down Tycoon 2FA The site had up to 2,000 users and operated more than 24,000 domains since its launch in August 2023. Microsoft said it seized 330 active domains powering the site and its control panels, under a court order from the U.S. District Court for the Southern District of New York. Together, they also identified the primary developer to be Saad Fridi, based in Pakistan. Coinbase said it helped trace the crypto payments that funded Tycoon’s operation and supported the civil action to seize the domains. The exchange said efforts are still ongoing with law enforcement to pursue the people who bought and used the Tycoon phishing service. “This was not a single phishing campaign. It was an industrialized service built to make MFA bypass accessible to thousands of criminals,” said Robert McArdle, Director for Cybercrime Research at TrendAITM, one of the partners. Crypto losses to phishing attack hit $83 million Earlier in January, Chainalysis reported that crypto scams are becoming increasingly industrialized with the rise of phishing-as-a-service and other tools. Some of the phishing kits are bought for under $500, but at scale, they can lead to millions of dollars in losses. “This modular, service-based approach is a force multiplier and allows even technically unsophisticated criminals to execute sophisticated phishing campaigns, substantially lowering the barrier to entry for cryptocurrency fraud,” Chainalysis wrote. Up to 106,106 victims lost their cryptocurrency to phishing attacks last year, though the figure was a lot lower than the year before. According to Scam Sniffer, crypto users lost $83.85 million, marking an 83% decline from the compared to $494 million recorded in 2024. Quarterly phishing losses. Source: Scam Sniffer Scam Sniffer found that phishing losses correlate with market activities. More losses were recorded in Q3, totaling $31 million, when ETH saw its strongest rally for the year, Cryptopolitan reported . If you're reading this, you’re already ahead. Stay there with our newsletter .

ChartModo Newsletter
Leggi la dichiarazione di non responsabilità : Tutti i contenuti forniti nel nostro sito Web, i siti con collegamento ipertestuale, le applicazioni associate, i forum, i blog, gli account dei social media e altre piattaforme ("Sito") sono solo per le vostre informazioni generali, procurati da fonti di terze parti. Non rilasciamo alcuna garanzia di alcun tipo in relazione al nostro contenuto, incluso ma non limitato a accuratezza e aggiornamento. Nessuna parte del contenuto che forniamo costituisce consulenza finanziaria, consulenza legale o qualsiasi altra forma di consulenza intesa per la vostra specifica dipendenza per qualsiasi scopo. Qualsiasi uso o affidamento sui nostri contenuti è esclusivamente a proprio rischio e discrezione. Devi condurre la tua ricerca, rivedere, analizzare e verificare i nostri contenuti prima di fare affidamento su di essi. Il trading è un'attività altamente rischiosa che può portare a perdite importanti, pertanto si prega di consultare il proprio consulente finanziario prima di prendere qualsiasi decisione. Nessun contenuto sul nostro sito è pensato per essere una sollecitazione o un'offerta