Skip to main content

【イベント】TrendAI™ Spark 2026 開催

AIセキュリティの最前線を探るグローバルイベント「Spark 2026」を全国5都市で開催します。

Return to TrendAI™ Security Blog
Cyber crime

TrendAI™ Intelligence Aids Law Enforcement Arrest of Tycoon 2FA Operators

The Singapore Police Force (SPF), working closely with Pakistan's National Cyber Crime Investigation Agency (NCCIA) and INTERPOL has arrested two individuals linked to Tycoon2FA, a phishing operation that served criminal customers across four continents.

News Cyber crime Research features

Key Takeaways

  • Singapore Police Force (SPF) and Pakistan's NCCIA announced the arrest of two individuals in Punjab tied to Tycoon2FA, a phishing-as-a-service (PhaaS) operation. This service was used in large-scale campaigns targeting Microsoft 365 and Google, using more than 24,000 domains since it first appeared in 2023.
  • Raids across Islamabad, Faisalabad, and Sialkot recovered computers, servers, mobile devices, and storage media. Four additional suspects fled the country before the raids; NCCIA has begun the process of seeking Interpol Red Notices against them. Proceeds from these illegal activities were funneled into real estate in Islamabad, which the NCCIA is now moving to confiscate.
  • This is a separate law enforcement action from the March 2026 coalition takedown of Tycoon 2FA's central infrastructure, an operation TrendAI™ supported alongside Europol, Microsoft, and other partners. That operation seized more than 300 domains; this week's arrests target individuals in Pakistan connected to standing up and operating infrastructure under the same Tycoon2FA brand.
  • Attribution intelligence TrendAI™ shared with Europol ahead of the March takedown was subsequently passed on to Interpol, where it formed part of the broader law enforcement picture surrounding the two arrests and Interpol Red Notice requests now being sought against the remaining four suspects who fled Pakistan before this week's raids.

Introduction

On August 3rd, 2026, the Singapore Police Force announced the arrest of two individuals in Punjab linked to Tycoon2FA. Additional details were provided in an earlier July 22 announcement from the NCCIA and reported in local media. This is a welcome follow-up to a long-term operation that TrendAI™ has been part of since its inception in 2025.

In March, we wrote about the coalition effort that took the core Tycoon 2FA PhaaS infrastructure offline. That operation was led by Microsoft and Europol, supported by TrendAI™ and a broad group of industry partners, and seized over 300 domains tied to the platform. At the time, we noted that disruption is rarely the end of the story: operators adapt, rebuild, and migrate, and previously stolen credentials and sessions remain in circulation long after a takedown notice goes up. From the start, the end goal was clear: true success would come in the form of arrests.

This week's law enforcement announcement shows the continuation of that work. Investigators arrested two individuals accused of developing and operating phishing infrastructure marketed under the Tycoon2FA name. Coordinated raids across Islamabad, Faisalabad, and Sialkot recovered computers, servers, phones, and other digital evidence. Four other suspects who fled the country before the raids are now the subject of Interpol Red Notice requests.

Figure 1. Arrested individuals in law enforcement custody
Figure 1. Arrested individuals in law enforcement custody

Image source: https://www.phoneworld.com.pk/nccia-tycoon2fa-phishing-syndicate-arrested-pakistan-2026/

Tycoon 2FA: The platform behind the brand

For those who didn't follow the March takedown closely, it's worth recapping what Tycoon 2FA actually is, and why an operation built under its name is worth taking seriously.

Tycoon 2FA first surfaced in August 2023 as a PhaaS kit purpose-built to defeat multi-factor authentication. Rather than just harvesting a static username and password, it places an adversary-in-the-middle (AitM) proxy between the victim and the real login page. That proxy relays the login flow live: as the victim types a password and enters an OTP or approves a push prompt, the kit captures the credentials, the MFA code, and the resulting session cookie in real time. A stolen session cookie can then be replayed to take over the account directly, sidestepping MFA entirely rather than needing to defeat it.

By the time of the March disruption, TrendAI™'s tracking put the platform's footprint at roughly 2,000 active criminal subscribers, operating across more than 24,000 domains used since the kit's 2023 debut. Proofpoint had separately reported large-scale campaigns run through the kit against Microsoft 365 and Google accounts. Later versions of the kit added stealth features designed to frustrate bot detection and automated analysis; it also expanded to target mobile browser sessions. This kind of incremental hardening made the platform progressively more difficult for defenders to fingerprint and for law enforcement to move against.

The subscription model is what made the scale of this phishing platform possible. Rather than requiring every criminal customer to build their own infrastructure or understand the mechanics of an AitM attack, Tycoon 2FA rented out a ready-made service: phishing domains, evasion tooling, and basic campaign management were all included.

Tycoon 2FA arrests

According to the law enforcement announcements, the operation functioned as a phishing-as-a-service business: rather than committing fraud directly, the arrested individuals built and rented out ready-made phishing kits to other criminal operators. The kits reproduced login pages for banks and other trusted institutions closely enough to fool victims, then distributed links to those pages through email, SMS, and WhatsApp. When a victim entered a username, password, or one-time passcode, that data was relayed instantly to the operators, the same adversary-in-the-middle mechanic that lets AitM-style kits defeat MFA even when a victim believes they're completing a legitimate login step.

One detail worth noting: investigators say proceeds from the operation were used to purchase high-value real estate in Islamabad, which NCCIA has now identified and moved to confiscate. Laundering phishing proceeds into property, rather than cash or crypto, is a pattern worth watching as cybercrime revenue increasingly looks for assets that are harder to trace and claw back. Confiscation proceedings like this one are a meaningful test of whether that money can still be recovered.

How this follows on from the infrastructure takedown

The March action dismantled Tycoon 2FA's central infrastructure and named the developer/operator persona TrendAI™ had tracked under the monikers "SaaadFridi" and "Mr_Xaad.

This operation follows a similar pattern seen in other PhaaS and malware disruptions: a recognizable brand and kit design tend to outlive any single infrastructure seizure, because the subscription model that makes these platforms profitable also makes them easy to relaunch.

The attribution work TrendAI™ shared with Europol ahead of the March takedown didn't stop with the domain seizure. Europol passed that intelligence on to Interpol, and this helped inform the wider law enforcement picture NCCIA is now acting on, including the basis for these arrests, as well as the Interpol Red Notice requests against the four suspects who fled Pakistan before the raids. It's a good illustration of why we treat attribution work as a long-term investment, rather than a one-time deliverable tied to a single takedown announcement. Intelligence gathered from takedowns and disruptions can be handed from one agency to another and prove valuable months later, in a different country, through a completely different arm of the law enforcement network.

Conclusion

The lessons from March remain unchanged. Sustained tracking and intelligence sharing between researchers and law enforcement are what turn a known threat into an arrestable one, and what lets a domestic agency like NCCIA build on groundwork laid by an international coalition. We congratulate Singapore’s Police Force (SPF), Pakistan's NCCIA and INTERPOL on a well-executed operation, and we'll be watching for updates on the Interpol Red Notice requests against the four suspects still at large, as well as any future criminal proceedings. We also would like to thank Europol for their collaboration on the information we have shared throughout the investigations into Tycoon2FA.

As with any ongoing case, the individuals named here are entitled to a presumption of innocence unless and until a court finds otherwise, and the facts as currently understood are based on public statements from Singapore Police Force and NCCIA—rather than a completed judicial process.

We'll also continue watching for any sign of Tycoon 2FA's return. Arrests carry more weight than infrastructure takedowns alone: unlike a seized domain, a defendant facing prosecution is harder to simply relaunch under a new name. It's reasonable to hope this disruption sticks in a way the March takedown, on its own, could not.