The Tycoon 2FA bust in Pakistan is one of the biggest cybercrime wins Pakistani law enforcement has ever scored on the world stage. In a joint operation with Singapore’s Police Force and Interpol, Pakistan’s National Cyber Crime Investigation Agency (NCCIA) arrested the two men believed to have built the Tycoon 2FA platform, a criminal service that helped hackers steal banking logins and beat two-factor authentication across 96,000 victims worldwide.
What Is Tycoon 2FA and Why Should Pakistanis Care?
Tycoon 2FA is not simple password theft. It first appeared in August 2023 as a phishing kit designed to bypass multi-factor authentication. It uses an adversary-in-the-middle proxy that sits between the victim and the real login page, silently capturing credentials, OTP codes, and session cookies in real time. Attackers then replay those session cookies to take over accounts even when MFA is switched on.
Think of it this way: you get a fake SMS or WhatsApp link that looks exactly like your bank. You type your password. You even enter the one-time code sent to your phone. The criminal’s server forwards everything to your real bank, logs in on your behalf, and you never know. Every Pakistani who banks online, uses mobile banking, or receives SMS OTPs for financial transactions is a potential target of this type of attack.
After its emergence, Tycoon 2FA rapidly became one of the most widespread phishing-as-a-service platforms, enabling campaigns that reached over 500,000 organisations each month worldwide. Even less-skilled criminals could rent the kit and bypass MFA without writing a single line of code.
How the Tycoon 2FA Bust in Pakistan Happened
In March 2026, Europol led an operation that disrupted the technical infrastructure of the Tycoon 2FA platform. After that, Singapore’s Cyber Command worked closely with Pakistan’s NCCIA and Interpol to share intelligence on the platform’s operators.
TrendAI researchers had been tracking the platform’s infrastructure and operator behaviour over a long period. By November 2025, they had linked the operation to an actor using the online names SaaadFridi and MrXaad, assessed to be the developer and primary operator behind the service.
That intelligence led to the identification of two Pakistani nationals believed to be the developers of Tycoon 2FA. Acting on that intelligence, the NCCIA arrested both suspects under Pakistan’s Prevention of Electronic Crimes Act 2016. The two arrests happened on 25 June 2026 and 1 July 2026.
Coordinated raids were carried out across Islamabad, Faisalabad, and Sialkot. The raids resulted in the seizure of computers, servers, mobile devices, and digital storage media believed to have been used in the criminal operation.
One detail that most global coverage missed: beyond the arrests, NCCIA also recovered significant digital evidence and started legal proceedings to confiscate real estate in Islamabad that investigators believe was purchased using cybercrime proceeds. This means the criminals were turning digital fraud profits into property, a money-laundering method that is increasingly common worldwide.
Investigators also revealed that four additional suspects fled Pakistan before the raids and are now subject to Interpol Red Notice requests. Red Notices are international alerts asking law enforcement in member countries to locate and provisionally arrest the named individuals.
Singapore Police Praise Pakistan’s Role
Singapore Police publicly commended NCCIA for dismantling the syndicate, calling it a major success in the global fight against transnational cybercrime. Federal Interior Minister Mohsin Naqvi called the operation a landmark achievement that reflected Pakistan’s growing capability to combat sophisticated cyber threats through international cooperation.
The Tycoon 2FA platform has been linked to more than 96,000 phishing victims worldwide. At least three cases were reported in Singapore between November 2025 and January 2026, where business email accounts were compromised despite the use of multi-factor authentication.
The Scale of the Tycoon 2FA Platform
The phishing-as-a-service model is what made this threat so structurally dangerous. Tycoon 2FA’s developers maintained and updated the kit while affiliates purchased access and ran campaigns without needing to understand the technical side. It mirrored legitimate software businesses, with tiered pricing, customer support, and product updates, putting enterprise-grade MFA bypass in the hands of criminals who previously lacked the technical skills to do it themselves.
Email security firm Proofpoint observed over three million messages linked to the phishing kit in February 2026 alone. Trend Micro, one of the private sector partners in the operation, noted that the platform had approximately 2,000 paying users at the time of the takedown.
Pakistan’s growing fintech scene makes this story especially relevant locally. As more Pakistanis move their money onto apps and digital wallets, the attack surface for this kind of phishing grows. If you want to understand the broader security challenges facing Pakistan’s digital finance industry, our coverage of the Pakistan FinTech Summit in Islamabad gives useful context on where the sector is heading.
What Happens Next and What You Should Do Now
TrendAI says it will continue monitoring for attempts to rebuild or rebrand the service under new infrastructure and is supporting follow-on investigations into identified users and administrators. Previously stolen credentials and session cookies may still be in circulation, which means continued caution is needed.
The takedown also reinforces an important message: standard MFA alone is not enough against adversary-in-the-middle phishing. Here is what you can do right now to stay safer:
- Do not click links in unexpected SMS or WhatsApp messages that ask you to log in to your bank or email. Go directly to the app or website yourself.
- Use passkeys or hardware security keys where your bank or email provider offers them. These are much harder for AiTM attacks to beat.
- Check your recent logins in your bank app and email account regularly. If you see a session from a city or device you do not recognise, change your password at once and contact your bank.
- Be sceptical of any page that asks for both your password AND your OTP. Legitimate services rarely ask for both in quick succession on an external link.
Pakistan’s PECA 2016 law was used to charge the arrested suspects. The law covers unauthorised access to data and computer systems, making it the primary legal tool for cybercrime prosecution in the country. You can read more about PECA and Pakistan’s electronic crimes framework on the NCCIA official website.
Frequently Asked Questions
What is Tycoon 2FA?
Tycoon 2FA is a criminal subscription service that lets hackers bypass two-factor authentication. It places a fake website between the victim and the real login page, capturing passwords, OTP codes, and session tokens in real time. The stolen session data is then used to access accounts even after MFA has been completed.
Who was arrested in the Pakistan Tycoon 2FA bust?
Two Pakistani nationals, believed to be the developers and primary operators of the platform, were arrested in Pakistan on 25 June 2026 and 1 July 2026. Raids were carried out in Islamabad, Faisalabad, and Sialkot. Four other suspects fled before the raids and are now subject to Interpol Red Notices.
Is my Pakistani bank account at risk from this type of attack?
The Tycoon 2FA platform is now disrupted, but similar tools exist. Any Pakistani using online banking or mobile payment apps can be targeted by AiTM phishing. Never click login links sent via SMS, email, or WhatsApp. Always open your banking app or website directly. Report suspicious messages to your bank and to NCCIA.
What role did TrendAI (Trend Micro) play in this operation?
TrendAI, Trend Micro’s AI-powered threat intelligence unit, tracked the platform’s infrastructure and operator behaviour over a long period. By late 2025 its researchers had linked the operation to specific online aliases. That intelligence was shared with Europol, Singapore Police, and Interpol, and ultimately led to the identification and arrest of the suspects in Pakistan.













