In March 2026, a law-enforcement operation disrupted Tycoon 2FA, seizing infrastructure that had previously accounted for 89 percent of the phishing-as-a-service market and 62 percent of phishing observed by Microsoft. Tycoon 2FA had been used in attacks against more than 500,000 organisations since 2023.

The disruption did not end the underlying attack pattern.

It scattered it.

Affiliates and operators migrated within weeks to Mamba 2FA, EvilProxy, Sneaky 2FA, and Whisper 2FA. Total attack volume across the four successor platforms rose from roughly 20 million to more than 23 million. The phishing-as-a-service economy proved to be a hydra, not a single business.

39% of Indian banks lag.

Proofpoint analysed 80 Indian banks in January 2026 and found that nearly two in five (39 percent) were lagging on the basic cybersecurity measures, leaving customers, staff, and stakeholders at higher risk of email-based impersonation. The figure is for primary regulated banking. The shadow figure for NBFCs, fintech, and BFSI-adjacent payment operators is almost certainly worse.

Email was the first attack surface most Indian enterprises ever defended against. It is still the worst.

But first, some catch-up on infra this week.

🚨 Cookies Are the New Credential

For most of the last decade, the email-security conversation in Indian enterprise was about anti-phishing filters and user awareness training.

That conversation is finishing.

Cookies are the new credential.

The modern phishing-as-a-service kit, whether Tycoon 2FA or its successors, runs an adversary-in-the-middle (AiTM) attack rather than a static credential-harvesting page. The mechanics are worth understanding because they break the assumption most Indian BFSI security teams operate under.

The user receives a phishing email with a link that looks plausible. The user clicks. Instead of landing on a fake login page, they land on a reverse proxy that the attacker controls. The reverse proxy fetches the real bank's login page in real time and shows it to the user. The user enters their credentials. The proxy forwards the credentials to the real bank. The bank challenges the user for MFA. The proxy forwards the MFA prompt back to the user. The user enters the MFA token. The proxy forwards the token to the real bank. The bank, satisfied, issues a session cookie. The proxy captures the session cookie and passes it along to the user, who now sees their account dashboard and assumes the login was legitimate.

The attacker now has the session cookie.

The attacker injects the cookie into their own browser and is logged in as the user, with MFA already satisfied, with no further authentication needed for the lifetime of the session.

The MFA was not bypassed. The MFA worked exactly as designed.

The session token that the MFA produced was stolen.

For the Indian BFSI security team that has spent the last 18 months congratulating itself on a 95-percent MFA-enforcement rate, the operational reality is uncomfortable. MFA-enforcement is a precondition, not a defence. The defence has to live at three other layers:

✔ Email-authentication enforcement (SPF + DKIM + DMARC at p=reject) so the phishing email never lands

✔ User-behavior detection so the suspicious click registers as anomalous

✔ Session-token monitoring so the attacker's first action with the stolen cookie triggers an alert

The first one is policy. The second one is platform. The third one is observability.

How we plug in: Our Business Communication practice runs the email-authentication enforcement work for Indian BFSI clients. SPF inventory across every sending domain. DKIM key rotation. DMARC posture migrated from p=none to p=quarantine to p=reject on a measured timeline, with the reporting hooks that prove the migration is working. We have done this work across BFSI, manufacturing, pharma, and textile clients. The email-security platform is one layer; the authentication-posture discipline underneath it is the floor.

🔍 Proofpoint, Mimecast, Defender for O365, Indian Domestic

Four categories of email-security vendor dominate the Indian BFSI procurement shortlist in 2026. Each is selling a different operational story.

Defender is the floor.

Proofpoint is the threat-intelligence and behavior-based detection leader. Two decades of dedicated email-security business, deep coverage on sophisticated BEC and executive-impersonation patterns. Enterprise pricing $25-70 per user per year for large organisations, with a procurement-side caveat: budget 20-40 percent more than the base quote for full functionality across DLP, TRAP, and CASB. Best fit for the regulated Indian BFSI buyer whose threat model leads with targeted impersonation and whose audit committee wants behavior-based detection in the platform.

Microsoft Defender for Office 365 is the floor for most Indian enterprises running M365. Plan 1 at $2 per user per month standalone. Defender provides a strong baseline of anti-phishing, anti-malware, and link rewriting. The trade-off honestly named: Defender is the foundation, not the complete stack. Organisations benefit from complementary tools that increase detection fidelity, reduce false negatives, and improve response speed. For an Indian buyer treating Defender as the floor and layering Proofpoint or Mimecast on top, the architecture is sound. For an Indian buyer treating Defender as the complete answer, the AiTM-phishing landscape is going to teach an expensive lesson.

Mimecast is the secure-email-gateway + continuity play. $6-10 per user per month for mid-size organisations. Operates as a gateway in front of M365, providing additional inspection plus the often-overlooked benefit of email continuity during Microsoft service outages. Bundles MX gateway, in-tenant scanning, archiving, encryption, DNS filtering, and security-awareness training into a single procurement. Best fit when the buyer wants a single-vendor bundle covering both the security and the operational-continuity sides.

Indian domestic vendors are the fourth category, increasingly relevant in 2026. Seqrite (Quick Heal subsidiary) ships AI-powered detection with behavioural analysis tuned to threat patterns targeting Indian enterprises, covering phishing, BEC, malware delivery, spam, and data exfiltration. eSec Forte, Microland, and the Indian IT-services majors (TCS, Wipro, Infosys, HCL) deliver email security as part of broader managed-services contracts, with the Indian-buyer-relationship advantage and locally tuned threat intelligence. For Indian BFSI buyers under DPDP-driven data-residency pressure, the Indian-domestic option is now a viable lead vendor rather than a fallback.

The four-vendor read-out, in one summary:

👉 Proofpoint: threat intelligence + behaviour-based detection. Best for sophisticated BEC threat models.

👉 Microsoft Defender for O365: the foundation. Layer something on top.

👉 Mimecast: gateway + continuity bundle. One-vendor procurement.

👉 Indian domestic (Seqrite + integrators): locally tuned + DPDP-friendly + cost-appropriate.

For most Indian BFSI buyers, the realistic 2026 answer is hybrid. Defender for O365 as the floor (which Microsoft licensing makes hard to avoid anyway). One complementary layer on top, picked based on threat-model fit. And an Indian-domestic SI or MSSP as the operational owner, regardless of which detection platform underlies the contract.

How we plug in: Our Complete IT Infrastructure Solution practice runs the email-security vendor-evaluation matrix for Indian BFSI buyers. We have done this work across banks, NBFCs, pharma majors, manufacturing groups, and textile conglomerates. The vendor's pricing slide leads with per-user/month. The procurement memo needs the architecture-fit assessment, the threat-model-mapping work, the integration with the existing identity stack, the integration with the existing SIEM/SOAR, and the realistic 3-year TCO once the complementary layers are factored in.

📌 India's Email-Security Reality: 265 Million Detections, $2.77B Global BEC, Top 5 Target

The Indian email-security situation in 2026 needs a clearer accounting than most procurement memos provide.

Per the Seqrite India Cyber Threat Report 2026, India recorded 265.52 million malware detections in 2025. Email remains the primary attack vector. Maharashtra, Uttar Pradesh, and Delhi are the three top hotspots by detection volume.

The FBI's BEC tracking recorded $2.77 billion in global BEC losses in 2024. Cumulative exposed loss now exceeds $51 billion. The financial sector carries the highest median per-incident loss at roughly $125,000. India consistently ranks in the top five targeted countries by BEC frequency, driven by a combination of large email-using enterprise population, English-language business communication, and well-known BFSI brand names that lend themselves to impersonation.

The 2026 evolution that matters: AI-generated phishing combined with BEC now accounts for an estimated 22 percent of incidents, increasingly enhanced with voice-cloned and deepfake content. The Indian BFSI executive who receives a WhatsApp audio message from "the MD" requesting an urgent transfer authorisation is now experiencing the voice-cloned attack, not just a poorly worded email. The Indian-language deepfake video is following close behind.

For the Indian BFSI CISO working backward from a 2027 audit, three operational priorities concentrate:

✔ Email-authentication posture (SPF + DKIM + DMARC) at enforcement, not just at observation. The DMARC record alone proves nothing.

✔ Inbound email-security platform at a depth that detects AiTM-phishing patterns, voice-cloned audio links, and deepfake-attachment vectors.

✔ Out-of-band verification protocols for any financial-transaction request received via email, regardless of how legitimate the sender appears. The MD does not authorise a ₹2 crore transfer over WhatsApp. Documented procedure beats heroic alertness.

The 39-percent figure from the Proofpoint analysis is not a future risk. It is the current operational reality at two of every five Indian banks today.

How we plug in: Our Business Communication practice runs the email-authentication posture migration for Indian BFSI buyers. From SPF inventory through DKIM rotation through DMARC enforcement, with the dashboards that prove the migration is working. We pair this with the inbound-email-security platform selection and the out-of-band verification procedure design. We have done this work across Indian BFSI, manufacturing, pharma, and textile clients for thirty-five years.

📋 The DMARC Mandate Is Live; The CERT-In Clock Is 6 Hours

The compliance landscape around email security in 2026 has hard deadlines that most Indian procurement memos still treat as advisory.

Two compliance pressures matter.

The DMARC enforcement mandate. Google, Yahoo, and Microsoft now require SPF + DKIM + DMARC with a published DMARC record for any domain sending more than 5,000 messages per day, with non-compliant mail rejected at the SMTP level. PCI DSS v4.0 mandates DMARC for any organisation handling cardholder data, with monthly fines of $5,000 to $100,000 for non-compliance. The mandate is global; the impact is Indian.

The reality check: only around 18 percent of the world's 10 million most-visited domains publish a valid DMARC record, and only around 4 percent fully enforce a reject policy. Global DMARC adoption sits at 52.1 percent overall. Fortune 500 adoption is 95 percent with 62.7 percent at p=reject. Inc 5000 adoption is 76.2 percent with only 15.2 percent at p=reject. The gap between "publishing a record" and "enforcing rejection" is where most organisations sit, including most Indian banks.

The CERT-In 6-hour reporting clock. Per the CERT-In Direction of April 2022, all organisations including banks, NBFCs, insurers, and payment aggregators operating in India must report cyber incidents within six hours of becoming aware. Failure carries penalties up to ₹1 lakh per day plus regulatory action through the sector regulator. Twenty categories of reportable incidents include phishing and BEC.

For BFSI, the reporting obligation is dual. Most regulated entities must report the same incident to both CERT-In and their sector regulator. Banks and NBFCs report to RBI. Brokers, AMCs, and depositories report to SEBI. Insurers report to IRDAI. The dual-reporting workflow needs to be tested before an incident, not during one.

For the Indian BFSI security team mapping the email-incident workflow, three contract clauses worth getting right with the email-security vendor:

👉 What does the incident-detection artefact look like, and can it be exported to the CERT-In incident-report template + the sector-regulator format in under six hours?

👉 What is the chain-of-custody documentation for email evidence, given DPDP data-residency expectations and regulator requirements for audit trail?

👉 What is the platform's behaviour if a CERT-In takedown request is issued against an Indian domain? Can the platform support the operational workflow on the receiving side?

The compliance framework is no longer separate from the email-security RFP. It is the procurement frame the RFP has to fit inside.

How we plug in: Our Cyberdefense practice reads the CERT-In reporting clock + the RBI / SEBI / IRDAI sector-regulator overlay for Indian BFSI clients. We have built the dual-reporting workflow for banks, NBFCs, and insurers, with the runbook tested before incidents land. The vendor's email-security platform is one piece. The reporting workflow that turns a detection into a compliant six-hour notification is the other piece. Both have to exist before the next BEC attempt arrives.

MFA-Bypass Phishing Spreads After Tycoon 2FA Takedown
Petri.
The primary-coverage read on the March 2026 disruption and the successor platforms. Read for the architectural detail on how Mamba, EvilProxy, Sneaky, and Whisper differ.

Proofpoint: Two in Five Indian Banks Are Leaving Customers at Risk of Email Fraud
Proofpoint, January 2026.
The primary source for the 39-percent figure. Useful in the procurement memo when the audit committee asks why the email-authentication posture matters for the Indian buyer specifically.

Seqrite India Cyber Threat Report 2026
Seqrite (Quick Heal).
The 265-million-detections-in-2025 primary source. Pair with the Indian-vendor side of the email-security shortlist.

CERT-In Direction for Reporting Cyber Incidents
Deloitte India.
The cleanest explainer on the six-hour reporting rule and the twenty categories of reportable incidents. Read before the next incident, not during.

DMARC, SPF, and DKIM in 2026: Why Email Authentication Is a Regulatory Requirement
DuoCircle.
The compliance-side explainer on the Google + Yahoo + Microsoft 5,000-message threshold and the PCI DSS v4.0 mandate. Read for the regulatory framing before the procurement memo.

💡 My Take

For most Indian enterprises, email security is the oldest part of the IT-security budget.

The anti-spam appliance arrived in 2005. The anti-phishing filter was added in 2010. The MFA enforcement project finished in 2018. The user-awareness-training contract renewed every year since.

That decade-plus of investment built a defence against a threat model that no longer exists.

Email is your audit log.

Every BFSI security incident that touches customer money in 2026 will leave an email trail. The phishing message that started the chain. The BEC reply that confirmed the wire instruction. The Slack-thread-via-email-notification that documented the escalation. The CERT-In report that closed the loop. The auditor reading the incident response twelve months later will read the email trail before they read anything else.

For the Indian BFSI CISO working backward from that auditor reading, the email-security stack is no longer just a defence layer. It is the documentation layer for everything else.

The reframe matters. The AiTM-phishing kit that steals a session cookie does not just bypass MFA. It bypasses the audit trail that the rest of the security stack depends on. The attacker logs in as the user, performs the action, and leaves no email trail because they were already authenticated. The fraud team chasing the money trail backwards finds an empty space where the documenting email should have been.

The defence has to live in three places that are not the email-security platform itself:

The authentication-posture discipline that prevents the inbound phishing from landing in the first place. SPF, DKIM, DMARC at p=reject, not at p=none.

The user-behaviour observability that catches the moment when a user clicks the link that should have been rejected. The same email-security platform usually has this; most procurement teams never turn it on.

The session-token monitoring that catches the moment when the stolen cookie is replayed. This is the layer most Indian BFSI security teams have not built yet, because the cookie-theft threat model was not common until late 2024.

VEMIO™ exists because the operational reality of running this kind of multi-layer email-security posture across an Indian BFSI book needs an observability layer that the email-security platform alone does not provide. The platform reports that the email was blocked. The CISO needs to see across the email blocks, the user-behaviour anomalies, the session-token replays, the CERT-In dual-reporting workflow, the SEBI / RBI / IRDAI parallel notifications, and the chain-of-custody audit artefacts. All in one operator view.

Email was your first attack surface in 2005. It is still your worst in 2026.

Reply to this email with the one email-authentication decision you are revisiting this quarter, and we will feature the most operationally interesting reply (anonymised, with consent) next issue.

Until next time,

Ajay Salvi & the Vinay Enterprises team.

Keep Reading