Punjab Busts International Tycoon2FA Phishing Syndicate Behind 96,000 Fake Banking Apps, Two Arrested
Punjab's NCCIA has arrested two members of an international phishing syndicate that built over 96,000 fake banking apps and fraudulent links under the Tycoon2FA infrastructure, supplying cybercriminals across four continents while investing proceeds in Islamabad real estate.

Punjab’s NCCIA has arrested two members of an international phishing syndicate that built over 96,000 fake banking apps, fraudulent links, and counterfeit platforms under the Tycoon2FA infrastructure, supplying cybercriminals across North America, South America, Central Asia, and Europe while investing proceeds in Islamabad real estate.
Cybercrime investigations rarely surface operations of this scale from within Pakistan. Tuesday’s announcement by the Punjab National Cyber Crime Investigation Agency exposes something more troubling than the typical online fraud case: a technically sophisticated, internationally connected phishing infrastructure built and operated from Pakistani soil, supplying criminal networks across four continents with the tools to steal banking credentials, OTPs, and social media accounts from victims worldwide.
What Was Uncovered
The NCCIA’s operation identified a highly organised cybercrime network using a phishing infrastructure the suspects had developed and named Tycoon2FA. Under this platform, the network created more than 96,000 phishing applications, fake accounts, and fraudulent links, a scale of output that required dedicated infrastructure, technical expertise, and coordinated distribution to sustain.
The Tycoon2FA infrastructure was not used only domestically. Investigators found that it was supplied to cybercriminals operating in Pakistan and internationally, across North America, South America, Central Asia, and Europe. The suspects were not simply committing fraud themselves. They were running a phishing-as-a-service operation, providing ready-made criminal tools to other bad actors globally in exchange for payment.
The operational mechanism was carefully designed. Suspects created fake websites that mimicked the login pages of well-known banks, companies, and government institutions with sufficient accuracy to deceive users. These fraudulent pages were distributed to victims through phishing links sent via email, SMS, and WhatsApp. When a victim entered their credentials, banking details, or one-time password on the fake page, the information was transmitted instantly to the suspects, enabling them to drain bank accounts or take complete control of the victim’s digital profiles before the victim realised anything had happened.
The network operated through Telegram and other encrypted platforms, a standard tactic for cybercrime organisations seeking to coordinate activity while minimising law enforcement visibility.
The Arrests and What Was Seized
Coordinated raids were conducted across three cities, Islamabad, Faisalabad, and Sialkot, reflecting the syndicate’s distributed operational footprint within Pakistan. NCCIA teams seized computers, laptops, servers, mobile phones, digital storage devices, and forensic evidence from the raided locations.
Two suspects were arrested. Both played central roles in developing and operating the Tycoon2FA phishing infrastructure; they were not peripheral members of the network but core architects of its technical capability. Four other key suspects had fled abroad before the raids could reach them. NCCIA has initiated the process of obtaining Interpol Red Notices against the absconding suspects, and liaison with law enforcement agencies in the relevant countries is ongoing to secure their arrest.
Proceeds Invested in Real Estate
One of the investigation’s most significant disclosures concerns how the proceeds of the fraud were handled. Investigators found that the suspects had invested funds obtained through cybercrime in high-value properties in Islamabad. The NCCIA has identified these properties and initiated legal proceedings to confiscate them and transfer them to state custody as proceeds of crime.
The real estate investment detail reveals the scale of the operation’s financial returns. Cybercrime proceeds significant enough to fund high-value property purchases in Islamabad represent a substantial volume of fraud and an attempt to launder digital crime proceeds into tangible, appreciating assets that are harder to trace than cryptocurrency or bank transfers.
The asset confiscation proceedings will be a test of Pakistan’s ability to pursue proceeds of cybercrime through the legal system, a capability that is increasingly important as cybercrime revenues are laundered through domestic property markets globally.
Tycoon2FA: A Known Threat Operated From Pakistan
The Tycoon2FA name carries specific significance in global cybersecurity circles. Tycoon2FA is a phishing kit that targets multi-factor authentication, specifically designed to bypass the two-factor authentication protections that banks and online services deploy to prevent account takeover even when a password has been stolen. By intercepting OTPs in real time, Tycoon2FA-based attacks can defeat security measures that users reasonably believe protect them.
The fact that infrastructure of this sophistication was being developed and operated from within Pakistan and supplied internationally represents a serious escalation in the technical capability of cybercrime networks with Pakistani connections. This is not unsophisticated SMS fraud or basic phishing. It is a purpose-built platform for bypassing modern authentication security at scale.
What Pakistani Internet Users Need to Know
The Tycoon2FA operation targeted Pakistani citizens alongside victims in other countries. Every Pakistani who banks online, uses mobile banking applications, or receives SMS OTPs for financial transactions is a potential target of this type of attack.
The attack mechanism is specific and worth understanding. A phishing link arrives via email, SMS, or WhatsApp, directing the user to a page that looks exactly like their bank or a trusted service. The user enters their credentials. The page may even prompt for an OTP, which the user enters, believing they are completing a legitimate authentication step. In the time it takes the user to complete the process, the syndicate has captured the credentials and OTP and is using them to access the real account.
Protection against this attack type requires vigilance about how you reach your bank’s website; always type the URL directly or use a saved bookmark rather than clicking links in messages, regardless of how official those messages appear. Never enter an OTP on a page you reached through a link sent to you. Contact your bank directly if you receive unexpected authentication requests.
The Bottom Line
The NCCIA’s Tycoon2FA bust is one of the most significant cybercrime enforcement actions Pakistan has taken, uncovering not just a fraud operation but a phishing infrastructure factory supplying criminal networks across multiple continents. Two arrests and four international fugitives, Interpol notices filed, real estate proceeds being confiscated, and evidence seized across three cities: the operation’s scale reflects the gravity of what was operating beneath Pakistan’s digital surface. The four suspects who fled abroad represent the investigation’s unfinished chapter, and the real test of whether Pakistan’s international law enforcement coordination can bring a globally connected cybercrime network to full account.
Mobile Phone Taxes Portal
Find the PTA Taxes on All Phones on a Single Page using our Taxes Portal.
Note: Mobile phone tax rates and calculations fall under the jurisdiction of the Federal Board of Revenue (FBR), not the Pakistan Telecommunication Authority (PTA).
Explore NowFollow us on Google News!