Breach404
Back to Insights
Cybersecurity2 min readMay 17, 2026

Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing

A new phishing attack called Tycoon2FA is targeting Microsoft 365 accounts by tricking users into approving device-code authentication requests, often delivered through compromised email tracking links from legitimate services like Trustifi. If attackers

Could your website be vulnerable to attacks like this?

Run a free 10-point security scan on your site — headers, SSL, DNS, and more. Results in 15 seconds.

Test Your Site Now — It's Free