Six United Bank Limited (UBL) customers have reportedly lost a combined Rs. 10.45 million in an alleged cyber fraud involving the misuse of confidential banking information and fraudulent replacement SIM cards.
According to the case record, fraudsters allegedly obtained customers’ confidential information, including their registered mobile numbers, from insiders. The information was then allegedly used to facilitate the issuance of duplicate SIM cards.
The victims’ original SIM cards were reportedly blocked before replacement SIMs were activated in their names. This allegedly allowed the suspects to gain access to mobile banking accounts and transfer funds.
The National Cyber Crime Investigation Agency (NCCIA) investigated the matter following complaints involving the alleged fraudulent issuance of duplicate SIMs using victims’ CNIC details and fingerprints.
Investigators also raided a telecom franchise allegedly linked to the case.
During the raid, authorities reportedly recovered SIM scanners, a biometric verification device, computers, mobile phones, and around 150 suspicious SIM cards.
The Lahore High Court (LHC) has also addressed the alleged misuse of confidential banking information.
Justice Tariq Saleem Sheikh dismissed the post-arrest bail petition of Muhammad Atif, a UBL Branch Services Supervisor accused of accessing and disclosing confidential customer information.
The court observed that investigation material, including bank records and account-access logs, provided sufficient grounds at the bail stage to proceed against him.
Meanwhile, the court granted post-arrest bail to Muhammad Usman, who was allegedly associated with a telecom franchise involved in issuing duplicate SIM cards, stating that further investigation was required in his case.
In an important observation, the LHC held that customer information maintained by banks can constitute “property” under Pakistani law.
The court referred to Section 27(2) of the Prevention of Electronic Crimes Act (PECA), which treats electronic data as property for certain offences under the Pakistan Penal Code.
The court noted that dishonest disclosure or unauthorized use of customer data by an employee entrusted with such information may, depending on the circumstances, amount to criminal breach of trust.
However, the court clarified that not every bank employee who has access to customer information would automatically be liable under Section 409 of the Pakistan Penal Code. The employee’s actual duties, authority, and control over the data must be examined.
The case highlights the risks created when banking information and mobile-number control are compromised simultaneously.
Fraudsters who gain access to both types of information may potentially bypass security measures protecting customers’ digital banking accounts.
The case also underscores the importance of stronger controls around confidential banking information, SIM replacement procedures, and biometric verification to prevent similar incidents.
