Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing

Source: BleepingComputer  ·  Category: Threat Actor & Campaign


Tycoon2FA phishing kit now supports device-code phishing and abuses Trustifi URLs to hijack Microsoft 365 accounts. Law firms depend on Microsoft 365; this is a direct threat to attorney and staff email accounts. Escalate to security team and user awareness program immediately.

→ Read the full article

Read more