Tycoon2FA Phishing Kit Evolves to Hijack Microsoft 365 Accounts: What Was Reportedly Exposed & What To Do
A phishing campaign leveraging an updated Tycoon2FA kit was reported on May 12, 2026, exposing credentials, account access, and OAuth tokens from an undisclosed number of Microsoft 365 users. Check your account activity and review connected applications for any signs of unauthorized access.
What happened
Public reporting on May 12, 2026, stated that the Tycoon2FA phishing-as-a-service kit now supports device-code phishing. The updated kit abuses Trustifi click-tracking URLs together with OAuth 2.0 device authorization flows to register unauthorized devices on Microsoft 365 tenants.
Once access is obtained, attackers can reach email, calendar, and cloud storage contents. The kit is reported to have persisted after a March law enforcement action. No figures for accounts compromised or data volumes have been released.
How a breach like this happens
Phishing kits of this type typically begin with messages that direct recipients to a controlled page. The page initiates an OAuth device-code flow, prompting the user to authorize a new device through a legitimate Microsoft endpoint.
Successful authorization returns tokens that allow persistent access without further user interaction. Kits often reuse trusted domains or tracking services to increase the chance that messages reach inboxes and that links are clicked.
About Tycoon2FA Phishing Kit Evolves to Hijack Microsoft 365 Accounts
Tycoon2FA is a phishing-as-a-service offering that supplies pre-built tools for credential capture and account takeover. Such kits are used by multiple operators and are updated over time to bypass detection and exploit common authentication mechanisms.
Microsoft 365 environments commonly contain business email, shared documents, and calendar data. Unauthorized access to these resources can expose internal communications and stored files for as long as the obtained tokens remain valid.
What was likely exposed
The reports name three categories of data associated with the kit’s new capabilities:
- credentials
- account-access
- oauth-tokens
Exact volumes, specific accounts, or additional data types have not been disclosed. Organizations that rely on Microsoft 365 routinely store email correspondence, calendar entries, and cloud-stored files; whether any of these were accessed in connection with the kit remains unconfirmed.
The real-world impact
Compromised OAuth tokens can allow continued access to Microsoft 365 resources even after a password change, until the tokens are revoked. This can result in ongoing visibility into email threads, meeting schedules, and document repositories.
For the affected accounts, the primary consequences are loss of confidentiality and the need for token revocation and account remediation. No monetary loss figures or confirmed downstream misuse have been published.
Were you affected?
Review recent Microsoft 365 sign-in logs for unfamiliar device registrations and revoke any unrecognized OAuth consents. Enable or verify multi-factor authentication and monitor for unexpected forwarding rules or mailbox access.
Readers can run a free exposure scan of their email address against known breach data to check whether their credentials have appeared in public listings.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Dashlane Brute-Force Attack Downloads <20 Encrypted VaultsVeil#Drop Framework Delivers PureLog Infostealer via BlogspotAdaptHealth Patient Data Stolen via Contractor PhishingMeta Discloses 20K Instagram Accounts Hijacked via AI Support ToolLatest breaches
Based on public reporting
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.