Cybercrime Agency Busts International Gang Impersonating Foreign Embassies, Arrests 12 in Punjab
Pakistan’s National Cyber Crime Investigation Agency (NCCIA) has dismantled an international fraud network that spent years impersonating officials from foreign embassies to swindle visa and immigration applicants out of millions of rupees, arresting 12 members of the gang in a major crackdown.
A Years-Long Scheme Targeting Visa Seekers
NCCIA Punjab Director Muhammad Ali Wasim announced the bust at a press conference on Tuesday, describing it as one of the agency’s most significant crackdowns on organised cross-border cybercrime. According to Wasim, the network had been impersonating officials from several foreign embassies, including those of Italy, Germany, Sweden, Oman, and Saudi Arabia, defrauding visa and immigration applicants over the course of several years.
The arrests were carried out during a raid on a fake call centre operating out of Bahria Town Phase IV in Rawalpindi, a location the gang had apparently been using to run its fraudulent operations.
A Sophisticated Digital Deception
What made this network particularly effective, according to investigators, was the level of technical sophistication behind its scheme. The suspects reportedly created fake Google business profiles, set up bogus websites, and forged official documents in order to impersonate staff working at genuine foreign diplomatic missions.
Beyond just creating fake profiles, the group went a step further by manipulating online search results, ensuring that victims searching for legitimate embassy contact details would instead be redirected toward fraudulent phone numbers under the gang’s control. To reinforce the deception, the suspects also reportedly used advanced call-forwarding techniques and caller ID spoofing technology, allowing them to route calls meant for official embassy telephone lines directly to their own numbers instead.
How the Scam Actually Played Out
Once victims made contact, believing they were speaking with legitimate embassy staff, the fraudsters would reach out through phone calls and WhatsApp messages, demanding substantial payments for services like visa appointments, immigration processing, and document verification, services that, in reality, had nothing to do with any actual embassy.
To make their impersonation more convincing and intimidating, some members of the gang reportedly appeared in video calls wearing Singapore Police uniforms, falsely presenting themselves as law enforcement officials in order to pressure victims into compliance. Investigators say the group’s mastermind had also specifically recruited individuals fluent in Arabic, including the Saudi dialect, along with speakers of other foreign languages, to make the impersonation of embassy staff and government representatives even more convincing to victims from different countries.
A Network That Had Been Operating Since 2019
According to NCCIA officials, this fraud network had been active since 2019, gradually expanding its operations over time to target victims in Oman and Saudi Arabia in addition to its original scope. Investigators say efforts are now underway to trace the group’s financial transactions, identify additional victims who may not have yet come forward, arrest remaining suspects still at large, and investigate the network’s broader international connections.
The operation that led to Tuesday’s arrests was carried out by the NCCIA’s Gujranwala Circle, and officials say a substantial amount of digital evidence was recovered during the raid, including 21 mobile phones, a vehicle, a Singapore Police uniform, forged appointment letters, phishing emails, fake Google business profiles, PTCL records, and multiple Gmail accounts, all of which have since been sent for forensic examination.
A Broader Message From Investigators
Wasim indicated that the agency intends to keep pursuing cybercrime networks that target the public by exploiting the names and credibility of government institutions and foreign diplomatic missions, framing this bust as part of an ongoing broader effort rather than an isolated success.
A Separate Case Targeting Banking Credentials
In a related but separate development, the NCCIA also arrested two individuals believed to be key figures behind a sophisticated phishing operation used to steal banking credentials and other sensitive personal data from victims both within Pakistan and abroad.
According to investigators, the suspects had developed and operated a phishing platform known as Tycoon2FA, comprising more than 96,000 fake applications, accounts, and malicious links used by cybercriminals across Pakistan, North and South America, Central Asia, and Europe. The suspects allegedly used counterfeit banking websites and pages mimicking legitimate government institutions and private companies to harvest victims’ usernames, passwords, one-time passwords, and banking details through phishing links distributed via email, SMS, and WhatsApp.
Coordinated raids in Islamabad, Faisalabad, and Sialkot led to the seizure of computers, laptops, servers, mobile phones, and various digital storage devices. Investigators say proceeds from the alleged fraud had been funnelled into high-value properties in Islamabad, and legal proceedings have already begun to confiscate those assets. According to the NCCIA, four additional suspects connected to this case have fled the country, and the process of securing Interpol Red Notices for their arrest is currently underway.
A Growing Pattern of Sophisticated Cyber Fraud
Taken together, these two cases highlight the increasingly sophisticated nature of cyber fraud networks operating out of Pakistan, ones capable of building convincing fake institutional identities, manipulating search engine results, spoofing caller ID systems, and running phishing infrastructure at a genuinely global scale. For law enforcement, tackling networks of this complexity requires not just traditional investigative work but increasingly specialised digital forensics capabilities, exactly the kind of expertise the NCCIA appears to be building out as it continues targeting these organised cybercrime operations.
Looking Ahead
With investigations continuing into the embassy impersonation network’s financial trail and international connections, and Interpol Red Notices being pursued for suspects who have fled abroad in the separate phishing case, both operations remain very much active rather than closed. For visa applicants and members of the public more broadly, these cases serve as a pointed reminder to verify embassy contact information directly through official government channels rather than relying on search engine results or unsolicited contact claiming to represent diplomatic missions.





