UBL Customers Face over Rs10 Million Losses as SIM Swap Threat Grows

Ubl Customers Face Over Rs10 Million Losses As Sim Swap Threat Grows

LAHORE – At least six UBL customers have reportedly suffered losses of over Rs10 million in alleged SIM swap fraud that gave suspects access to mobile banking accounts adding concerns over security of confidential banking data and SIM replacement procedures.

The customers allegedly lost combined Rs10,458,500 after fraudsters got their hands on confidential banking data, blocked their genuine SIM cards, and activated duplicate SIMs to hijack their mobile-banking accounts.

Justice Tariq Saleem Sheikh, in a consolidated order dated 17 June 2026, rejected the post-arrest bail plea of Muhammad Atif, a UBL Branch Services Supervisor accused of leaking customer data, while granting bail to Muhammad Usman, linked to the telecom franchise used to issue the fraudulent SIMs.

The case started when Pakistan Telecommunication Authority (PTA) complained to the National Cyber Crime Investigation Agency (NCCIA), Lahore, after two UBL customers Sultan Masood Malik and Shabbir Hussain reported duplicate SIMs fraudulently issued against their CNICs and used to drain their accounts.

PTA traced duplicate SIM for Malik, activated 9 November 2025, to a transfer of Rs555,000, and one for Hussain, activated 6 November 2025, to a transfer of Rs422,500. Both were linked to Jazz Franchise ID No. 6561, operating as Fine Telecom in Yazman, and to a Biometric Verification System (BVS) device bearing IMEI No. 867332036305067.

NCCIA registered FIR No. 316/2025 on 18 November 2025 under the Prevention of Electronic Crimes Act (PECA), 2016, read with sections of the Pakistan Penal Code (PPC), including forgery, fraud, and, later, criminal breach of trust under Section 409 PPC.

MCB ordered to refund victim in online fraud case

A joint NCCIA-PTA raid on Fine Telecom the same day recovered two SIM scanners, one BVS device, one CPU, one laptop, and around 150 suspicious SIM cards. Muhammad Usman was apprehended at the scene alongside two co-accused, who have since secured bail from a trial court. As the probe widened, four more victims emerged, taking the confirmed loss to Rs10.45 million across six accounts.

UBL’s Fraud Risk Management Division produced two internal reports, both pointing to insider access including confidential customer data, including registered mobile numbers, that had allegedly leaked from within the bank, with access logs showing suspicious staff activity.

Muhammad Atif, Branch Services Supervisor at UBL’s District Courts, Jhang branch, was named in these reports. Investigators allege he accessed customer records through the bank’s CRS system and disclosed registered mobile numbers at the request of an Omni-services staffer, who passed the information to an absconding accused. His defence — that he was merely verifying contact numbers — was found by the court to have no rational basis.

Central to ruling is Section 27(2) of PECA, which extends “property” in any property-related offence to include “information system and data.” Justice Sheikh held this brings electronic customer data within the scope of Sections 405–409 PPC (criminal breach of trust) — meaning an employee who dishonestly discloses or misuses entrusted customer information can, in principle, be treated as having misappropriated property.

The court drew a line, however: not every bank employee qualifies as a “banker” under Section 409 PPC, the only charge carrying life imprisonment and falling within the “prohibitory clause” that makes bail harder to secure. The test set out: the data must be the kind used to access or operate customer accounts, and the employee must have gained entrustment or dominion over it through actual banking duties — not incidental access.

Applying this, the court found sufficient material against Muhammad Atif given his supervisory role and the cumulative evidence, and dismissed his bail plea.

Muhammad Usman’s case differed. Though Fine Telecom is registered in his father’s name, prosecutors allege he ran it. But the evidence against him, WhatsApp messages and an email flagging misuse of the BVS device, dated, after fraudulent activations was found too thin, with no forensic proof linking him to the SIM-swaps or bank insiders. The judge ruled his case needs “further inquiry” and granted bail against Rs1,000,000 in bonds.

The ruling shows that Pakistani courts will treat leaked customer data as seriously as stolen property, holding bank staff to a “banker’s” standard of trust over digital account access. With SIM-swap fraud combining insider banking access and compromised telecom verification, the case sharpens scrutiny of biometric SIM-issuance controls, franchise oversight, and internal bank-data security. The trial continues, with the court noting its bail-stage findings are tentative and non-binding.

SBP issues directives to commercial banks regarding ATM transactions

Get Alerts