Skip to content
Email Spoofing Exploit via Misconfigured Routing

Email Spoofing Exploit via Misconfigured Routing

First seen 7 Jan 2026, 17:41 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

Attackers are exploiting misconfigured email routing to spoof internal emails, utilizing PhaaS platforms like Tycoon2FA to steal credentials. This tactic allows phishing actors to bypass spoof protections and send emails that appear to originate from within organizations, targeting their domains.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 182d ago How this analysis works

More articles in this cluster (4)

Following this threat?

Track Tycoon2FA in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed