M Siddique Ali Pirzada
Pakistan today occupies a pivotal yet increasingly precarious digital juncture in which the promise of financial inclusion through mobile banking and fintech expansion is being rapidly eclipsed by an industrial-scale escalation in cyber-enabled financial fraud.
This evolution exposes not only vulnerabilities in digital infrastructure but also deeper institutional and regulatory deficits within the country’s enforcement architecture. The empirical record is stark: the Federal Investigation Agency’s 2024 data records over 73,000 cybercrime complaints, yet only 1,604 cases were formally registered, revealing a profound mismatch between victimisation and prosecutorial capacity.
Visa’s research further suggests that nearly every second Pakistani encountered some form of online financial fraud in 2024, with one in five experiencing repeated victimisation. Meanwhile, the Banking Ombudsman’s resolution of nearly 28,000 complaints, yielding PKR 1.65 billion in recoveries, while operationally meaningful, remains marginal when measured against the scale of aggregate losses and the steady erosion of public trust in digital finance. Compounding this is an emerging behavioural withdrawal: a significant segment of the population continues to avoid or limit online banking altogether, , thereby constraining the very financial inclusion agenda digitisation was meant to advance.
This fragility is unfolding alongside intensified regulatory stress and mounting evidence of systemic vulnerability within the banking sector itself. The State Bank of Pakistan imposed over PKR 776 million in fines in Q1 2024 on major banks for deficiencies in anti-money laundering compliance, customer due diligence and fraud controls, even as cybercrime surged by 35 percent in 2025 according to the National Cyber Crime Investigation Agency, with Karachi alone accounting for 29,000 complaints. The State Bank also reported a 62 percent increase in banking fraud, while Kaspersky documented a 114 percent year-on-year rise in financial malware attacks, underscoring a decisive shift from opportunistic scams to coordinated, technologically sophisticated intrusions targeting financial infrastructure. Increasingly, these attacks are concentrated within mobile-first ecosystems, where smartphone-dependent users constitute the majority of new entrants into formal banking systems, rendering the security perimeter both decentralised and fragile.
The evolving typology of cyber threats reflects a rapidly adaptive criminal economy. WhatsApp-based impersonation, OTP theft, phishing campaigns mimicking institutions such as banks, the FBR and NADRA and SIM-swap operations designed to intercept authentication channels now constitute dominant vectors of exploitation. Parallel to this, illicit financial ecosystems are expanding at scale: the NCCIA’s dismantling of a Faisalabad-based Ponzi network involving 149 arrests, alongside the Securities and Exchange Commission of Pakistan’s identification of 141 fraudulent lending applications, signals the deep embedding of digital fraud within Pakistan’s financial periphery. At the infrastructural level, the scale of compromise is accelerating. Over 5.3 million device-level cyberattacks and 166,000 banking malware detections were recorded in the first three quarters of 2025, alongside web-based threats affecting a significant share of users and institutions. Yet this technological threat landscape is amplified by a parallel crisis of human and institutional capacity. According to the Digital Rights Foundation, only 28 percent of users can reliably identify cyber threats, while over 60 percent of firms lack basic cybersecurity safeguards such as encryption and multi-factor authentication. This weakness is particularly acute in small and medium-sized enterprises, which constitute nearly 85 percent of Pakistan’s business landscape but remain structurally under-equipped to manage digital risk. Institutionally, enforcement capacity remains severely constrained. Approximately 350 cybercrime investigators are tasked with handling over 160,000 cases, creating unsustainable caseloads that undermine timely investigation and deterrence. Fragmented jurisdiction between the Federal Investigation Agency and the National Cyber Crime Investigation Agency further weakens coordination, while limited forensic infrastructure across provinces restricts the state’s ability to trace, prosecute and deter increasingly transnational fraud networks. The result is not merely operational inefficiency but a broader governance deficit, reflected in Gallup Pakistan’s finding that two-thirds of citizens lack confidence in the state’s ability to prevent cybercrime. This erosion of trust becomes self-reinforcing: underreporting increases, deterrence weakens and fraud ecosystems gain further operational space.
Preventive literacy remains the most immediate and cost-effective line of defence. Citizens must be trained to enable two-factor authentication across all financial platforms, verify investment and lending schemes through the Securities and Exchange Commission of Pakistan’s official registry and report fraud swiftly via Banking Mohtasib and NCCIA helplines to improve recovery outcomes. At the enterprise level, cybersecurity audits and mandatory training on phishing and social engineering should be baseline requirements, particularly for SMEs, which are the most exposed entry point in the digital economy. While laws such as the PECA 2016 Act and the National Cybersecurity Policy 2021 provide a framework, they remain insufficient without stronger enforcement, coordination and sustained investment in digital literacy. Cybercrime already costs Pakistan an estimated USD 2.8 billion annually, about 1.2 percent of GDP, undermining digital growth and financial inclusion. The challenge is no longer access to technology but the credibility and resilience of the systems that secure it.
—The writer is a commentator on International and Comparative Law.

