
April 14, 2026

In early 2026, Microsoft and Europol dismantled Tycoon 2FA - a phishing-as-a-service platform that had, by mid-2025, accounted for an estimated 62% of the phishing attempts Microsoft blocked globally. The platform had sent an estimated 87.5 million phishing messages targeting over 500,000 organisations. Its entry price was approximately $120 per month.
Tycoon 2FA is gone. The technique it used is not. Adversary-in-the-middle (AiTM) reverse proxy attacks - where an attacker's infrastructure sits between a victim and a legitimate login page, capturing credentials and session tokens in real time - are now a commodity. Kits like EvilProxy, BlackForce, Starkiller, and GhostFrame offer the same capability, with subscription pricing, dashboards, and customer support. The barrier to bypassing conventional MFA has collapsed.
For enterprise CISOs, the question is no longer whether to implement MFA. The question is whether the MFA you have deployed actually protects against the attacks you are facing - and for most organisations, the honest answer is: not entirely.
The fundamental problem with SMS codes, authenticator app TOTP codes, and push notifications is that they all operate within the browser authentication flow. When a user enters a code into a browser, an AiTM proxy can capture it and relay it to the real service in real time - before the code expires. The session token that results is then stolen by the attacker. The user completed MFA correctly. The attacker is now authenticated.
Session cookie theft compounds this. Recorded Future's 2025 Identity Threat Landscape Report found that 276 million of the credentials indexed in 2025 included active session cookies - meaning attackers did not even need to replay a code. They simply presented a stolen cookie to a web application and bypassed authentication entirely. The average compromised device yielded 87 stolen credentials spanning corporate applications, personal accounts, and cloud services.
A FIDO2 hardware security key - such as a YubiKey - does not transmit a code. It performs a cryptographic challenge-response that is bound to the origin domain of the website being authenticated against. If an AiTM proxy intercepts the authentication request and presents it from a different domain - even a pixel-perfect replica - the key will refuse to respond. The attack fails structurally, not because the attacker made a mistake, but because the protocol does not allow it.
This is the distinction that matters. SMS codes, TOTP codes, and push approvals can all be intercepted or manipulated because they exist in the communication layer between the user and the server. A FIDO2 authentication is a direct cryptographic assertion from the hardware device to the server. There is no code to intercept. There is no approval to manipulate. There is no session to steal from the authentication event itself.
For organisations managing privileged access, remote workers, or high-value systems - the populations that attackers target first - this structural difference is not a marginal improvement. It is the difference between an authentication method that can be defeated with a $120 toolkit and one that cannot.
Deployment at scale
The most common friction point in enterprise hardware key deployments is not the technology - it is logistics. Distributing physical devices to employees across multiple locations, managing replacements, and coordinating enrolment at scale requires operational infrastructure that most IT teams have not previously needed. Direct-to-employee fulfilment, coordinated across offices and remote workers simultaneously, is increasingly a requirement rather than a nice-to-have.
Fallback authentication
Hardware keys are only as strong as the fallback methods permitted when a key is unavailable. A robust hardware key deployment that permits SMS as a fallback for lost keys is not phishing-resistant - it is phishing-resistant except when it matters most. Fallback policy design is as important as the key selection itself.
Coverage scope
Partial deployment creates a residual risk surface. Attackers will identify and target the accounts within an organisation that have not been migrated to phishing-resistant authentication. Privileged accounts and remote access are the minimum viable scope. Full workforce coverage is the only way to eliminate the residual surface.
Regulatory alignment
FIDO2 hardware authentication satisfies phishing-resistant MFA requirements under the ASD Essential Eight Maturity Level 3, NZISM controls for privileged and remote access, and NIS2 requirements for critical and important entities in the European Union. For organisations subject to any of these frameworks, hardware security keys are not an optional enhancement - they are a compliance pathway.
Trust Panda is a Yubico Gold Partner and Authorised eCommerce Partner - one of a small number of partners globally to hold this status. Our team has completed Yubico 100, 200, and 300 level certifications, with more than 20 Yubico-certified engineers across our global operations. We have delivered hardware authentication deployments to enterprise clients across 50 countries, coordinated from five global distribution locations.
We work with enterprise security teams from initial deployment planning through to direct-to-employee fulfilment, fallback policy design, and ongoing key management. If you are evaluating phishing-resistant authentication for your organisation, we are well-placed to support that process.