Historical intelligence backfill. This assessment covers reporting originally published on 2026-03-04 and was added to the RWP archive on 2026-09-07.
Tycoon2FA was MFA-bypass as a monthly subscription — Microsoft's March disruption moved the volume, not the motive
Storm-1747's Tycoon2FA kit pushed tens of millions of AiTM messages a month until a DCU/Europol domain seizure in March 2026; Q2 volume later fell about 92% off the 2025 baseline.
Bottom line up front
CONFIRMED Tycoon2FA, run by the actor Microsoft tracks as Storm-1747, was a leading AiTM phishing-as-a-service platform from 2023 into 2026. Microsoft's 4 March 2026 technical blog and DCU legal post describe kits starting around $120/10 days or $350/month, clone pages for Microsoft 365/OneDrive/Outlook/SharePoint/Gmail, and session theft that survives a password reset unless tokens are revoked. DCU, with a SDNY order and Europol CIEP coordination, seized 330 domains. DCU said that by mid-2025 Tycoon2FA was about 62% of phishing Microsoft blocked, including more than 30 million emails in a single month. Q2 2026 email-landscape reporting later put Tycoon-linked volume ~92% below H2 2025 averages (15.1 million/month down toward 1.2 million in June).
IT-009 (Q2 email landscape) is a trend piece that depends on this disruption; it will be a separate post, not merged.
Historical backfill of 4 March 2026 reporting; added 7 September 2026.
What happened
PhaaS industrialized AiTM: customer panel on Telegram/Signal, fake login, steal cookie, sell access. Microsoft names a primary developer in the DCU narrative (Saad Fridi, believed Pakistan-based) plus partners for marketing and payments. Treat that attribution as Microsoft/legal-claim CONFIRMED in their filing narrative, not independently retried here.
The January 2026 routing/spoof article (already in this archive) is how some of those messages looked internal. This March piece is the kit and the takedown.
Why it mattered
"We have MFA" was the board slide. Tycoon2FA's product was "MFA is a speed bump." Token theft, not password reuse, is the failure mode. Disruption worked on this brand's volume; Q2 data also showed Teams vishing filling some of the gap. Kill one marketplace, watch the channel shift.
Who / what was affected
Microsoft: 500,000+ organizations reached per month at peak in their telemetry. Horizontal. OT not claimed.
Technical context
Defenses that survive kit rebrands: phishing-resistant MFA (FIDO2), token/session revocation playbooks, Conditional Access that hates new countries and impossible travel, mailbox rules after a phish. Seizing 330 domains is not a control you can run in-house; reducing phishable MFA is.
Exploitation / threat status at the time
CONFIRMED kit scale, AiTM, domain seizure, later volume collapse in Microsoft telemetry.
REPORTED rebuild attempts in Q2 without recovering scale.
UNKNOWN how much migrated to unnamed successor kits.
What defenders should have done
- FIDO2 for anyone with mail forwarding, payroll, or admin.
- After any suspected AiTM: revoke refresh tokens, not just reset password.
- Hunt consent grants and inbox rules, not just "bad From:".
- Expect vishing/Teams as the overflow — that is Q2's measured shift.
What we know now
Q2 2026 numbers are the after-action: disruption can work, and actors move to voice. Do not declare phishing over.
RWP assessment
Confidence: High on Microsoft-observed volume and the seizure. Moderate that 92% is Tycoon-tagged volume, not all phishing.
Defensive actions
- Passkeys for privileged users.
- Token revocation runbook tested.
- Help-desk: no MFA reset from an inbound call that started the incident.
Sources
- Microsoft Threat Intelligence — Inside Tycoon2FA
- Microsoft Digital Crimes Unit — How a global coalition disrupted Tycoon 2FA
- Microsoft Threat Intelligence — Email threat landscape Q2 2026