Global coalition dismantles Tycoon 2FA phishing kit

2026-03-05T02:51:41Zae940c35de4dde6eb9ee383fd3bbf3569a74ca775f999fa94791dc9b0236fba1
2FALeakBaseMicrosoftTycoonagentic-ai-browsersandroid-patchcloud-identity-attackscloudflarecometcorunacybercrime-forumsdeepfakesdomain-seizureios-exploit-kitlaw-enforcementllm-deanonymizationlocal-file-exfiltrationphishingqualcomm-zero-daywinter-shield

What happened

A range of major cyber events and research findings: Microsoft led an international effort that seized 330 domains and helped dismantle the Tycoon 2FA phishing kit (with the alleged creator named in a civil complaint). Authorities from 14 countries also seized LeakBase, a large cybercrime forum, and arrested multiple suspects after obtaining its database. Security vendors and researchers disclosed actively exploited vulnerabilities and exploit kits — Google released a March Android security update fixing a Qualcomm zero-day among 129 Android vulnerabilities, and researchers traced the Coruna i

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cyberscoop
Record identifier
ae940c35de4dde6eb9ee383fd3bbf3569a74ca775f999fa94791dc9b0236fba1
Enrichment time
2026-03-05T02:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Global coalition dismantles Tycoon 2FA phishing kit · Baitaphish