Pakistan orders probe into SIM data breach after minister’s personal details exposed

Pakistan orders probe into SIM data breach after minister’s personal details exposed

By Staff Reporter

ISLAMABAD: Interior Minister Mohsin Naqvi has ordered an urgent investigation into a major data breach involving the leakage of mobile phone SIM card information, including his own, raising alarm over the vulnerability of personal data in the country.

The breach, which media reports claim has seen sensitive information sold on platforms like Google, underscores Pakistan’s ongoing struggle to secure its digital infrastructure amid rising cyber threats.

On Sunday, the Interior Ministry issued an official press release announcing the formation of a special investigation team under the National Cyber Crimes Investigation Agency to probe the matter. “Following the interior minister’s directives, the National Cyber Crimes Investigation Agency has constituted a special investigation team to probe into the matter and submit its report within 14 days,” the statement said.

The team is tasked with examining the circumstances of the breach and identifying those responsible, with the ministry vowing to bring culprits to justice through legal action. The scale of the breach, as reported by local media, is staggering. Data belonging to all SIM card holders in Pakistan, including detailed personal information, is allegedly being sold online.

According to reports, mobile location data is being offered for as little as Rs500, mobile data records for Rs2,000, and details of foreign trips for Rs5,000. The accessibility and low cost of this sensitive information have heightened concerns about privacy and security in a country already grappling with cyber vulnerabilities.

This latest incident follows a troubling pattern of data breaches in Pakistan. Just months ago, in early 2025, the National Cyber Emergency Response Team of Pakistan (PKCERT), a federal entity responsible for safeguarding the nation’s digital assets, issued a warning about a global data breach that compromised the login credentials and passwords of more than 180 million internet users in Pakistan.

Media reports, citing PKCERT’s advisory, revealed that the breach involved a publicly accessible, unencrypted file containing over 184 million unique account credentials worldwide. The advisory described the leaked database as a product of infostealer malware, which extracts sensitive information from compromised systems and stores it in plain text without encryption or password protection. “The breach exposed user names, passwords, emails, and associated URLs tied to major social media services, as well as government portals, banking institutions, and healthcare platforms worldwide,” the advisory stated.

It warned that the stolen credentials could enable account takeovers, identity theft, and unauthorized access to sensitive government and business portals. PKCERT highlighted the risks posed by the unprotected database, noting that it included login information for major platforms, enterprises, government agencies, and financial institutions.

The advisory outlined several potential threats, including credential stuffing attacks—where attackers use stolen passwords across multiple services—phishing campaigns leveraging exposed emails, targeted social engineering, unauthorized access to accounts, and malware deployment. To mitigate these risks, PKCERT urged individuals to change their passwords annually and use credible online services to check for potential breaches. Pakistan’s cybersecurity challenges are not new. In March 2024, a Joint Investigation Team (JIT) formed to investigate a data leak from the National Database and Registration Authority (Nadra) reported that the personal information of approximately 2.7 million people had been compromised between 2019 and 2023. The Nadra breach, which involved sensitive citizen data, raised serious questions about the security of Pakistan’s national databases and prompted calls for stronger safeguards.

The recurring nature of these incidents has amplified public and official concern about the country’s ability to protect sensitive information. PKCERT, tasked with defending Pakistan’s digital infrastructure from cyberattacks, cyberterrorism, and cyber espionage, faces mounting pressure to address vulnerabilities in a rapidly digitizing society. The agency’s advisory emphasized the need for proactive measures, such as regular password updates and heightened awareness of phishing and social engineering tactics.

Copyright © 2021 Independent Pakistan | All rights reserved