The National Computer Emergency Response Team (National CERT) has detected a phishing campaign in which fake websites, set up in the names of key government institutions, are being used to steal sensitive information of citizens.
In a statement, The Threat Intelligence Center of the National CERT said suspicious domains were found active on October 4 in the names of multiple national bodies, including the National Database and Registration Authority (NADRA).
The identified sites include a fake “secure login” domain using the NADRA name.
The statement said fake domains impersonating the Federal Board of Revenue (FBR), Higher Education Commission (HEC), Pakistan Telecommunication Authority (PTA) and Federal Investigation Agency (FIA) were also found active.
Similar domains were detected in the names of the Securities and Exchange Commission of Pakistan (SECP), Benazir Income Support Programme (BISP) and the Prime Minister’s Youth Programme.
A suspicious login domain was also identified in the name of Punjab Safe Cities. According to the statement, the phishing domains remain active.
The National CERT said it is continuously monitoring threats involving fake websites and institutional impersonation. It urged citizens and government departments to remain cautious of suspicious links, websites and login pages.