Tycoon2FA Microsoft 365 Account Hijacking Device-Code Phishing | MSSP Advisory
High
DateMay 17, 2026
📋Executive Summary
The Tycoon2FA phishing kit now supports device code phishing attacks targeting Microsoft 365 accounts by abusing OAuth device authorization flows and Trustifi email security service click-tracking URLs. Attackers send convincing phishing emails that redirect victims to fake Microsoft login pages where entering credentials triggers a device code request that appears legitimate on the real Microsoft authentication page. Once victims approve the device code, attackers gain persistent access to Microsoft 365 accounts even if passwords are later changed.
⚠️Why It Matters for MSSPs
Your RMM and PSA platforms likely authenticate through Microsoft 365, making your entire client stack vulnerable if your admin accounts get compromised through this attack vector. Every client running Microsoft 365 faces immediate risk because this technique bypasses traditional phishing detection and creates persistent access tokens that survive password resets.
📬
Get notified when client-ready advisories like this are published each week.
Join the MSSP Watchlist →🏷️Threat Category
Phishing
Partner MSSPs receive the full advisory — talking points, actions, and social posts — under their own brand.