Soneri Bank Manager arrested as NCCIA probes Citizens’ Data Leak

Soneri Bank Manager Arrested As Nccia Probes Citizens Data Leak

LAHORE – For just few hundred rupees per record, thousands of Pakistani citizens’ sensitive identity details were allegedly being sold to online fraudsters by Soneri Bank operations manager who had access to NADRA’s verification system, exposing disturbing potential breach of personal data security.

National Cyber Crime Investigation Agency (NCCIA), Lahore Zone, detained Irfan Ashraf, an operations manager at a bank branch in Arifwala, Punjab, over allegations that he misused the National Database and Registration Authority’s (NADRA) Verisys system to obtain citizens’ identity records and supply them to people involved in online fraud.

@waqasviews Soneri Bank Manager arrested over selling customers data to scamers #nccia #waqasviews #ScammerAlert #SoneriBank ♬ original sound – Waqas Ahmed (Reporter)

NCCIA Lahore Zone Additional Director Atif Ameer confirmed the arrest and details of the case, according to the Associated Press of Pakistan (APP) report published on October 10, 2026.

Technical examination of the suspect’s mobile phone reportedly revealed WhatsApp conversations containing thousands of Verisys records belonging to Pakistani citizens. Preliminary findings show that the suspect allegedly accessed the identity-verification system using his authorised credentials before passing the information to online fraudsters in exchange for small payments.

Investigators are now working to identify the recipients, trace the flow of money and determine how the stolen information may have been used. According to the NCCIA’s preliminary findings, the records allegedly obtained by the suspect primarily concerned elderly and deceased citizens, raising further questions about the possible targeting of vulnerable individuals.

The alleged operation reportedly began with a Facebook advertisement offering a job as a verification officer. Investigators say the suspect subsequently connected with the people behind the offer and began supplying citizens’ identity information without meeting the recipients in person.

Payments were allegedly made through JazzCash, with the suspect receiving a few hundred rupees for each record. The transactions reportedly passed through a mobile wallet registered in the name of an elderly person.

Authorities are investigating whether the account holder knowingly participated in the suspected scheme and are attempting to trace the individuals who allegedly purchased the information.

Some secondary reports have alleged that approximately 130 identity records were sold daily at Rs150 apiece, with estimated earnings of Rs12,000 to Rs15,000 per day. However, these figures have not been confirmed in the available official account and should not be treated as established facts.

UBL Fraud Case

A separate case involving United Bank Limited (UBL), a Branch Services Supervisor identified in reports as Muhammad Atif, associated with the bank’s District Courts branch in Jhang, was accused of disclosing customers’ registered mobile numbers.

MCB Ex-Manager arrested at Lahore Airport in Rs10 Million Investment Fraud Case

The leaked information allegedly helped criminals carry out SIM-swap fraud, resulting in unauthorised transfers exceeding Rs10.45 million from six accounts. A Jazz franchise operator was also linked to the alleged issuance of duplicate SIM cards.

Mini NADRA website exposed data of millions

Concerns over the protection of personal information have also surfaced in other cybercrime investigations reported in Pakistan during 2025 and 2026. Last month, two suspects were reportedly arrested over an alleged online operation described as “Mini NADRA”. Authorities reportedly recovered around three terabytes of data, including SIM ownership information, call detail records, family-tree information and location data associated with more than 10 million citizens.

In July 2026, three suspects were reportedly arrested in Lahore over the alleged sale of telecommunications data, including call records, SIM information, location details and biometric information. The investigation reportedly followed a complaint to the Pakistan Telecommunication Authority (PTA), and multiple devices and SIM cards were seized.

Allied Bank Multan Locker found Empty with 80 Tolas of Gold Missing; Manager on the run

Other reported cases have involved a NADRA official and an associate accused of selling records through WhatsApp in Hyderabad, as well as suspected networks trading CNIC, passport and telecommunications information.

The alleged misuse of identity records has wider implications because stolen personal information can potentially help criminals impersonate victims, obtain duplicate SIM cards, circumvent verification procedures or attempt to gain access to financial accounts.

PTA has reportedly blocked 18.2 million fraudulent SIM cards over a period of two and a half years. Separate joint operations involving the PTA and NCCIA have reportedly recovered thousands of SIM cards and ATM cards, along with biometric information associated with approximately 600,000 people.

Other reported fraud schemes have involved criminals impersonating bank officials to obtain one-time passwords, account credentials and confidential customer details. Investigators have also examined the use of intermediary accounts to receive or transfer funds linked to suspected financial crime.

These broader cases illustrate potential weaknesses across banking, identity-verification and telecommunications systems, although they do not establish that every method was used in the Arifwala investigation.

The investigation into the Arifwala bank manager remains ongoing, with the NCCIA attempting to establish who received the citizens’ records, how the payments were arranged and whether additional individuals were involved. The case raises serious questions about safeguards governing access to sensitive identity databases and the potential consequences when authorised access is allegedly misused.

Get Alerts