Pakistan telecom regulator says SIM data leak not from licensed operators

Pakistan telecom regulator says SIM data leak not from licensed operators

By Staff Reporter

ISLAMABAD: Pakistan’s telecommunications regulator said an audit found no security breaches in the licensed sector after media reports alleged that sensitive mobile SIM card data, including that of Interior Minister Mohsin Naqvi, was being sold online.

The Pakistan Telecommunication Authority, in a statement on Tuesday, said it had reviewed the claims and determined that the datasets appeared to originate from multiple external sources rather than telecom operators. The reports highlighted prices for the purportedly leaked information: mobile location data at Rs500, call and data records at Rs2,000, and details of foreign trips at Rs5,000.

“PTA clarifies it does not hold or manage subscriber data, which remains solely with licensed operators,” the authority said. “Initial review shows the reported datasets include family details, travel records, vehicle registrations, and CNIC copies, indicating aggregation from multiple external sources, not telecom operators. PTA’s audits have found no breaches within the licensed sector.”

The regulator added that it has blocked 1,372 websites, apps and social media pages involved in selling or sharing personal data as part of an ongoing crackdown on unlawful content. It noted that the Ministry of Interior has formed an inquiry committee to probe the matter.

Naqvi has ordered an urgent investigation into the breach, which includes his own SIM information, according to the Interior Ministry. The incident underscores Pakistan’s persistent challenges in securing digital infrastructure against escalating cyber threats.

On Sunday, the ministry announced the formation of a special investigation team under the National Cyber Crimes Investigation Agency. “Following the interior minister’s directives, the National Cyber Crimes Investigation Agency has constituted a special investigation team to probe into the matter and submit its report within 14 days,” the statement said.

The team will examine the circumstances of the breach and identify those responsible, with the ministry pledging legal action against culprits. Local media reports described the scale as encompassing data from all SIM card holders in Pakistan, with the information allegedly available on platforms including Google.

This episode follows a series of data security lapses in the country. A couple of months ago, the National Cyber Emergency Response Team of Pakistan, or PKCERT, issued an advisory about a global data breach that compromised the login credentials and passwords of more than 180 million internet users in Pakistan.

Media reports, citing the advisory, said PKCERT had identified the breach involving a publicly accessible, unencrypted file containing more than 184 million unique account credentials worldwide. The advisory described the leaked database as a product of infostealer malware, which extracts sensitive information from compromised systems and stores it in plain text without encryption or password protection.

Copyright © 2021 Independent Pakistan | All rights reserved