capital · May 18, 2026
eSentire Threat Research Unit Details Tycoon 2FA Operators Adopting OAuth Device Code Phishing
Share the canonical public link.
eSentire Threat Response Unit analysts published a report on Tycoon 2FA operators adopting OAuth device code phishing to bypass MFA and gain Microsoft 365 access. The report, shared with Cyber Security News, identified the campaign in late April 2026 after the March 2026 Microsoft and Europol coalition takedown left the core kit largely intact. Analysts noted operators now use user-agents like node, undici, and axios while polling client signatures during token acquisition. eSentire Threat Response Unit recommends organizations implement Microsoft Entra Conditional Access policies to block OAuth Device Code flows for regular end-users.