Hacking Humans · N2K Networks

Who’s logging in? [OMITB]

April 7, 2026·4 min
The button gets pressed, somehow. The cold open turns an unlabeled control into a running bit, with the hosts trying not to make the voice effects worse. Nobody trusts the buttons after that. It is silly, but it fits the security mood: one wrong click, one mystery option, and suddenly everyone is trying to figure out what just happened. Tycoon is the real story. The speaker calls it the biggest MFA credential phishing threat in their data, while Microsoft research also saw millions and millions of emails tied to the Tycoon phishing as a service platform. The episode does not treat it like a throwaway kit. It had support, updates, tools, and enough polish that buyers could get moving without much friction. That ease of use is the ugly part. The conversation pushes back on treating credential phishing as background noise. Malware gets the flashier attention. Botnets, wipers, Luma Stealer, Peekabot, and ransomware-linked infrastructure sound more technical, so phishing kits can be easier to underrate by law enforcement and the security research community. But phishing still opens the door. Once someone captures MFA-protected credentials, they can impersonate a person inside a company and start hunting for money, data, or leverage. The risk does not stop there. Stolen access can be sold to a more sophisticated actor who wants a clean entry point for malware deployment. That is the useful shift in the episode: MFA phishing kits belong in the ransomware and fraud supply chain, not off to the side as low-status scam tooling. The ad break is clear, with a ThreatLocker sponsor read after the Tycoon discussion, and the close moves into production credits, rating and review housekeeping, and sponsor thanks.

As heard by us

A clear, grounded look at MFA phishing kits and why stolen logins still matter.

"Who's logging in?" makes identity compromise feel less routine than its reputation suggests. Selina Larson opens with the kind of loose studio chaos Only Malware in the Building likes, then settles into Tycoon, an MFA credential phishing platform described as popular with…

Read the full review in PlayNext →

Why you'd press play

A fake login kit becomes a real doorway into someone else’s account.

Read the full recommendation in PlayNext →
Listen to the show on