Coinbase, in collaboration with Microsoft, Europol, and over ten other organizations, has dismantled the phishing-as-a-service platform Tycoon 2FA, seizing 330 associated domains. Launched in August 2023, Tycoon 2FA had around 2,000 users and operated over 24,000 domains, sending millions of fraudulent emails monthly to over 500,000 businesses globally. The platform exploited session cookies and tokens to bypass multi-factor authentication, targeting services like Microsoft 365, Outlook, and Gmail. Coinbase played a crucial role in tracing the cryptocurrency payment systems that financed Tycoon's operations and supported the civil lawsuit for the domain seizures. The operation identified Saad Fridi, a Pakistani national, as the main developer behind the platform.