Punjab National Cyber Crime Investigation Agency (NCCIA) has dismantled part of an international cyber fraud syndicate involved in large scale online financial scams targeting individuals in Pakistan and several other countries. The agency confirmed that two key members of the network have been sacked during coordinated operations, while investigations are continuing to trace other suspects believed to be operating from overseas. Officials said the operation uncovered an organised cybercrime network that relied on sophisticated phishing infrastructure, fake digital platforms, and advanced cyber technologies to steal sensitive information before carrying out financial fraud involving millions of rupees.
According to NCCIA, the investigation revealed that the suspects had developed and operated an advanced phishing infrastructure known as Tycoon2FA. Through this platform, they allegedly created more than 96,000 phishing applications, fake online accounts, and fraudulent links designed to deceive victims. Authorities said the infrastructure was supplied to cybercriminals operating not only in Pakistan but also across North America, South America, Central Asia, and Europe, allowing them to conduct large scale financial fraud campaigns. Investigators found that the network was managed through Telegram and other encrypted online communication platforms. The suspects allegedly created fake banking websites and web pages that closely resembled those of well known companies and government institutions before distributing phishing links through email, SMS, and WhatsApp. Once victims entered usernames, passwords, banking credentials, or one time passwords, the stolen information was immediately transmitted to the operators, allowing them to gain control of bank accounts or withdraw funds without the victims’ knowledge.
The investigation also revealed that proceeds generated from the cyber fraud were allegedly invested in high value properties located in Islamabad. NCCIA stated that these properties have been identified and legal proceedings are underway to confiscate them as assets obtained through criminal activity and transfer them into state custody. During coordinated raids conducted in Islamabad, Faisalabad, and Sialkot, investigators recovered a significant amount of digital evidence, including computers, laptops, servers, mobile phones, digital storage devices, and other materials required for forensic examination. Officials said the two individuals taken into custody were directly involved in the development and operation of the phishing infrastructure that supported the wider criminal network. The agency believes the recovered evidence will play an important role in identifying additional members, mapping the syndicate’s operations, and supporting further legal proceedings against those involved.
NCCIA also confirmed that four other key suspects linked to the international cybercrime network managed to flee abroad before the operation. The agency has initiated the process of obtaining Interpol Red Notices for the absconding individuals and is coordinating with law enforcement authorities in the relevant countries to facilitate their detention and return. Officials said the investigation remains active as authorities continue analysing the seized digital evidence to identify additional victims, uncover the full extent of the syndicate’s operations, and trace financial transactions connected to the fraud. NCCIA said the operation reflects its ongoing efforts to disrupt organised cybercrime networks involved in phishing attacks, financial fraud, and the misuse of digital platforms targeting individuals and institutions across multiple regions.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.