Global coalition dismantles Tycoon 2FA phishing kit
2026-03-05T02:51:41Z•ae940c35de4dde6eb9ee383fd3bbf3569a74ca775f999fa94791dc9b0236fba1
2FALeakBaseMicrosoftTycoonagentic-ai-browsersandroid-patchcloud-identity-attackscloudflarecometcorunacybercrime-forumsdeepfakesdomain-seizureios-exploit-kitlaw-enforcementllm-deanonymizationlocal-file-exfiltrationphishingqualcomm-zero-daywinter-shield
What happened
A range of major cyber events and research findings: Microsoft led an international effort that seized 330 domains and helped dismantle the Tycoon 2FA phishing kit (with the alleged creator named in a civil complaint). Authorities from 14 countries also seized LeakBase, a large cybercrime forum, and arrested multiple suspects after obtaining its database. Security vendors and researchers disclosed actively exploited vulnerabilities and exploit kits — Google released a March Android security update fixing a Qualcomm zero-day among 129 Android vulnerabilities, and researchers traced the Coruna i
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cyberscoop
- Record identifier
- ae940c35de4dde6eb9ee383fd3bbf3569a74ca775f999fa94791dc9b0236fba1
- Enrichment time
- 2026-03-05T02:51:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.