Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 20, 2026 (about 3 months ago).

people · May 20, 2026

eSentire Threat Research Unit Documents Tycoon 2FA OAuth Device-Code Phishing Variant

Share the canonical public link.

Share as image

eSentire Threat Research Unit documented Tycoon 2FA operators adopting OAuth device-code phishing in late April 2026 following March 2026 law-enforcement takedown. The variant routes victims through a four-layer obfuscated delivery chain to complete MFA at the real Microsoft login page and hand over long-lived access tokens. Every business running Microsoft 365 remains in scope without needing a CVE or misconfiguration. Push Security reports a 37x increase in device-code phishing this year across at least 10 PhaaS platforms.

Below validation threshold — auto-passed without scoring

Supporting evidence