people · May 15, 2026
eSentire Threat Response Unit Analyzes Tycoon 2FA Phishing Campaign
Share the canonical public link.
eSentire Threat Response Unit analyzed a phishing campaign in late April 2026 combining Tycoon 2FA operations with OAuth device-code grant phishing. The operators repurposed their Phishing-as-a-Service kit to deliver the OAuth phishing framework, targeting users across multiple sectors. The campaign exploits legitimate OAuth flows to bypass traditional 2FA protections and gain unauthorized access to accounts. eSentire detected the activity through its managed detection and response services monitoring client environments. The report details technical indicators including specific phishing domains registered on April 20, 2026.