A sophisticated cyber fraud network impersonated officials from multiple foreign embassies for nearly seven years, swindling visa and immigration applicants out of millions of rupees before a major crackdown by Pakistan's cybercrime agency. Main Developments The National Cyber Crime Investigation Agency (NCCIA) arrested 12 members of an international gang that posed as staff from the embassies of Italy, Germany, Sweden, Oman, and Saudi Arabia. The arrests occurred during a raid on a fake call center in Bahria Town Phase IV, Rawalpindi, according to NCCIA Punjab Director Muhammad Ali Wasim. The fraudsters created fake Google business profiles, bogus websites, and forged official documents. They manipulated online search results so that victims seeking embassy contact details were redirected to fraudulent phone numbers controlled by the gang. The network also used call-forwarding and caller ID spoofing technologies to route official embassy phone numbers to their own lines. Read also: 4 Reasons KP Lawmakers Call Anti-Militant Operations 'Aimless Victims were contacted via phone calls and WhatsApp, with fraudsters demanding large payments for visa appointments, immigration processing, document verification, and other consular services. To build trust, gang members appeared in video calls wearing Singapore Police uniforms and falsely claimed to be law enforcement officials. The NCCIA seized 21 mobile phones, a car, a Singapore Police uniform, forged appointment letters, phishing emails, fake Google business profiles, PTCL records, multiple Gmail accounts, and other digital evidence—all sent for forensic examination. The agency also arrested two key members of a related cyber fraud network operating the Tycoon2FA phishing platform, which comprised over 96,000 fake applications, accounts, and malicious links. Background The network had been active since 2019 and later expanded its operations to Oman and Saudi Arabia. The mastermind recruited individuals fluent in Arabic, including the Saudi dialect, along with other foreign languages, to strengthen the deception by posing as embassy staff and government representatives. The operation was carried out by the NCCIA's Gujranwala Circle. In a separate case, the NCCIA uncovered a phishing infrastructure that used counterfeit banking websites and pages mimicking government institutions and private companies. This operation stole usernames, passwords, one-time passwords (OTPs), and banking details from victims in Pakistan and abroad through phishing links sent via email, SMS, and WhatsApp. Why It Matters The scam exploited public trust in official diplomatic channels and undermined the integrity of visa and immigration processes for thousands of applicants. The NCCIA director emphasized that such networks target citizens seeking legitimate services, causing financial harm and eroding confidence in government institutions. The case also highlights the growing sophistication of cross-border cybercrime, with fraudsters using advanced technology and multilingual teams to deceive victims. The proceeds from the alleged fraud were invested in high-value properties in Islamabad, with legal proceedings initiated to confiscate those assets. This demonstrates how cybercrime profits can be laundered into real estate, further impacting the economy. What's Next The NCCIA is tracing the group's financial transactions, identifying additional victims, and arresting absconding suspects. Four other suspects have fled abroad, and the process of obtaining Interpol Red Notices for their arrest is underway. Coordinated raids in Islamabad, Faisalabad, and Sialkot have already led to the seizure of computers, laptops, servers, and digital storage devices from the suspects.