TrendAI™️ has strengthened its role in AI powered cyber threat intelligence after its attribution research contributed to an international law enforcement investigation targeting operators linked to the Tycoon 2FA phishing as a service platform. The operation, announced by the Singapore Police Force, involved close cooperation with Pakistan’s National Cyber Crime Investigation Agency (NCCIA) and INTERPOL and resulted in two suspected operators being sacked in Punjab. Coordinated raids were conducted across Islamabad, Faisalabad and Sialkot, during which authorities seized computers, servers, mobile devices and digital storage media believed to have been used in cybercriminal activities. Investigators also found that four additional suspects had left Pakistan before the raids and are now subject to INTERPOL Red Notice requests as authorities continue efforts to trace individuals allegedly connected to the operation.
According to TrendAI™️, the latest action represents another phase in a long running international effort to disrupt Tycoon 2FA and its underlying criminal infrastructure. Earlier this year, TrendAI worked with Europol, Microsoft and other cybersecurity partners to support efforts targeting the platform’s core infrastructure. That operation resulted in the seizure of more than 300 malicious domains associated with Tycoon 2FA. While the earlier action focused heavily on disrupting the infrastructure supporting the phishing service, the latest investigation concentrated on identifying the individuals responsible for developing and operating the infrastructure behind the Tycoon 2FA brand. TrendAI’s attribution intelligence was shared with Europol and contributed to the wider investigation by providing information that helped law enforcement agencies trace the network and coordinate enforcement activity across different jurisdictions.
Pakistan’s NCCIA played a central role in the domestic investigation and enforcement activities connected to the case. In addition to the seizure of digital devices and storage media, investigators recovered significant digital evidence that could assist in establishing the activities and connections of those involved. NCCIA has also initiated legal proceedings seeking the confiscation of real estate in Islamabad that investigators believe was acquired using proceeds generated through cybercrime. The development highlights the broader financial dimension of cybercrime investigations, where authorities increasingly seek to trace and restrict assets allegedly connected to illegal online activities. The cooperation between Pakistani authorities and international agencies also demonstrates how investigations involving cybercrime networks can require coordinated action across several countries, particularly when the infrastructure, operators and victims are located in different jurisdictions.
Tycoon 2FA emerged in 2023 and became one of the more sophisticated phishing as a service platforms used by cybercriminals to bypass multi factor authentication. The platform employed adversary in the middle, or AiTM, techniques to capture credentials and active user sessions, allowing attackers to target accounts protected by MFA. Since its emergence, Tycoon 2FA has been linked to more than 24,000 phishing domains and campaigns targeting Microsoft 365 and Google users across multiple continents. TrendAI™️ researchers have tracked the platform’s development since 2025 and generated intelligence that has supported efforts by international law enforcement agencies to disrupt its infrastructure and identify members of its operational network. The latest investigation underscores the role of threat intelligence in connecting technical indicators with real world investigations and enforcement actions.
The cooperation involving TrendAI™️, NCCIA, Singapore Police Force, INTERPOL and Europol reflects the growing importance of intelligence sharing between cybersecurity companies and law enforcement agencies in addressing cross border cybercrime. Cybercriminal groups increasingly rely on infrastructure and operations spread across multiple jurisdictions, making timely access to technical intelligence important for identifying individuals, mapping criminal networks and disrupting services used to target organizations and individuals. The latest action against individuals linked to Tycoon 2FA marks a significant development in the wider effort to counter phishing as a service operations. TrendAI™️ has reaffirmed its commitment to supporting governments, enterprises and law enforcement agencies through AI driven threat intelligence aimed at helping identify, investigate and disrupt emerging cyber threats before they can affect organizations and citizens.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.