Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 18, 2026 (about 4 months ago).

capital · May 18, 2026

eSentire Threat Research Unit Details Tycoon 2FA Operators Adopting OAuth Device Code Phishing

Share the canonical public link.

Share as image

eSentire Threat Response Unit analysts published a report on Tycoon 2FA operators adopting OAuth device code phishing to bypass MFA and gain Microsoft 365 access. The report, shared with Cyber Security News, identified the campaign in late April 2026 after the March 2026 Microsoft and Europol coalition takedown left the core kit largely intact. Analysts noted operators now use user-agents like node, undici, and axios while polling client signatures during token acquisition. eSentire Threat Response Unit recommends organizations implement Microsoft Entra Conditional Access policies to block OAuth Device Code flows for regular end-users.

Spend governor blocked model creation: provider_circuit_open (lane=dev, provider=together)

Supporting evidence