LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Tycoon2FA Phishing Kit Evolves to Hijack Microsoft 365 Accounts

HIGH severityReportedHow we verify

Tycoon2FA Phishing Kit Evolves to Hijack Microsoft 365 Accounts: What Was Reportedly Exposed & What To Do

RBRecent Breaches Breach Intelligence·May 12, 2026
Tycoon2FA Phishing Kit Evolves to Hijack Microsoft 365 Accounts

Reported May 12, 2026.

HIGH
Severity
3
Data types exposed
May 12, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

A phishing campaign leveraging an updated Tycoon2FA kit was reported on May 12, 2026, exposing credentials, account access, and OAuth tokens from an undisclosed number of Microsoft 365 users. Check your account activity and review connected applications for any signs of unauthorized access.

Severity & verification
HIGH severityReported
Account credentials exposed.
Based on public reporting. Not independently confirmed by the named organization.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On May 12, 2026, reports described an evolution of the Tycoon2FA phishing kit that adds support for device-code phishing attacks against Microsoft 365 accounts. The kit, which had already survived a law enforcement disruption in March, now uses Trustifi click-tracking URLs and OAuth 2.0 device authorization flows to register rogue devices and obtain access to email, calendar, and cloud storage. The number of people affected remains unknown, and no specific victim organizations or incident dates beyond the reported evolution have been disclosed.

What happened

Public reporting on May 12, 2026, stated that the Tycoon2FA phishing-as-a-service kit now supports device-code phishing. The updated kit abuses Trustifi click-tracking URLs together with OAuth 2.0 device authorization flows to register unauthorized devices on Microsoft 365 tenants.

Once access is obtained, attackers can reach email, calendar, and cloud storage contents. The kit is reported to have persisted after a March law enforcement action. No figures for accounts compromised or data volumes have been released.

How a breach like this happens

Phishing kits of this type typically begin with messages that direct recipients to a controlled page. The page initiates an OAuth device-code flow, prompting the user to authorize a new device through a legitimate Microsoft endpoint.

Successful authorization returns tokens that allow persistent access without further user interaction. Kits often reuse trusted domains or tracking services to increase the chance that messages reach inboxes and that links are clicked.

About Tycoon2FA Phishing Kit Evolves to Hijack Microsoft 365 Accounts

Tycoon2FA is a phishing-as-a-service offering that supplies pre-built tools for credential capture and account takeover. Such kits are used by multiple operators and are updated over time to bypass detection and exploit common authentication mechanisms.

Microsoft 365 environments commonly contain business email, shared documents, and calendar data. Unauthorized access to these resources can expose internal communications and stored files for as long as the obtained tokens remain valid.

What was likely exposed

The reports name three categories of data associated with the kit’s new capabilities:

Exact volumes, specific accounts, or additional data types have not been disclosed. Organizations that rely on Microsoft 365 routinely store email correspondence, calendar entries, and cloud-stored files; whether any of these were accessed in connection with the kit remains unconfirmed.

The real-world impact

Compromised OAuth tokens can allow continued access to Microsoft 365 resources even after a password change, until the tokens are revoked. This can result in ongoing visibility into email threads, meeting schedules, and document repositories.

For the affected accounts, the primary consequences are loss of confidentiality and the need for token revocation and account remediation. No monetary loss figures or confirmed downstream misuse have been published.

Were you affected?

Review recent Microsoft 365 sign-in logs for unfamiliar device registrations and revoke any unrecognized OAuth consents. Enable or verify multi-factor authentication and monitor for unexpected forwarding rules or mailbox access.

Readers can run a free exposure scan of their email address against known breach data to check whether their credentials have appeared in public listings.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Method

More recent breaches

Dashlane Brute-Force Attack Downloads <20 Encrypted VaultsJune 2, 2026Veil#Drop Framework Delivers PureLog Infostealer via BlogspotJuly 1, 2026AdaptHealth Patient Data Stolen via Contractor PhishingJune 27, 2026Meta Discloses 20K Instagram Accounts Hijacked via AI Support ToolJune 5, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Tycoon2FA Phishing Kit Evolves to Hijack Microsoft 365 Accounts →

Source: BleepingComputer

Based on public reporting

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram