Two arrested in Pakistan over development of the Tycoon2FA phishing platform

The Singapore Police Force stated on 3 August 2026 that two people suspected of developing the phishing platform Tycoon2FA have been arrested in Pakistan. The arrests followed cooperation between the Singapore Police Force, INTERPOL and Pakistan's National Cyber Crime Investigation Agency. According to the police the platform is linked to more than 96,000 victims globally. Several of the cases in Singapore involved business email accounts that were compromised even though multi-factor authentication was in place. The arrests follow an international operation that disrupted the Tycoon2FA infrastructure in March 2026.

What happens technically

Tycoon2FA is sold as phishing as a service. The buyer needs no development work and gets ready made copies of login pages for Microsoft 365 and other services. The copies are convincing enough that the user cannot tell the real page from the false one.

The bypass of multi-factor authentication uses a technique known as adversary in the middle. The platform sits between the victim and the real service, receives the username, the password and the one time code, and passes all of it on in real time. The service sees an entirely normal login and issues a valid session. That session, in the form of a cookie, ends up with the attacker. This is what makes the attack serious. With a stolen session cookie the attacker never has to repeat the second factor, because the login has already been completed. The police description of the victims in Singapore, where accounts were compromised despite multi-factor authentication, matches exactly this mechanism.

Usersigns in on a fake pageTycoon2FAsits in the middleReal serviceaccepts the loginSession cookieends up with the attacker
Figure: The password and the one time code pass straight through the middle. The service sees a normal login, and the attacker is left with a valid session.

What this means for you if you are responsible for account security

Arrests are good news, but our assessment is that you cannot lean on them. The operation in March 2026 disrupted the infrastructure. The case is nonetheless back five months later, with new victims and new investigative steps. The phishing as a service model keeps the skill with a few developers while the use spreads to a large number of buyers. When the developers are arrested the buyers do not disappear, and they usually find a new supplier.

The practical lesson for you is that a one time code is not the end of the road. Controls that bind the login to a device or a key, meaning passkeys or certificate based login, remove what makes the attack possible. You should also treat session cookies as valuable in their own right. That means short lifetimes, a fresh login when risk changes, and monitoring of logins from new devices and unexpected countries. If your organisation is covered by NIS2, this belongs under Article 21, both as access control and as incident handling.

Berigo recommends

  • Move to phishing resistant login where possible, meaning passkeys or certificate based sign in, and start with accounts that reach email and payments.
  • Shorten session cookie lifetimes for administrators and finance staff, and require a fresh login when risk changes.
  • Monitor logins from new devices, new countries and unusual clients, and send the alert to someone who actually acts on it.
  • Rehearse what happens after an account is compromised, meaning who terminates the session, who informs customers and who checks mail forwarding rules.
  • Teach staff that the right password and the right one time code prove nothing about whether the page is genuine.

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch