
A massive biometric data haul and millions of blocked SIMs expose dangerous gaps in Pakistan’s digital identity system, raising fresh questions about data security.
Pakistan’s digital identity infrastructure is facing renewed scrutiny after the National Cyber Crime Investigation Agency (NCCIA) told a National Assembly committee that biometric records belonging to around 600,000 citizens were recovered during a single raid. The disclosure came as officials detailed how stolen personal data, illegal SIMs and bank accounts are being exploited in financial crimes.
The scale of the alleged criminal activity was further illustrated by the arrest of a suspect in Faisalabad who was reportedly found with 195 active mobile SIMs, 16 smartphones and 81 ATM cards issued by different banks. Authorities said stolen biometric information and illegally obtained SIMs were being used to facilitate financial fraud, while rented bank accounts have emerged as another channel for criminals seeking to move illicit funds.
The Pakistan Telecommunication Authority (PTA) told lawmakers that approximately 18.2 million SIMs had been blocked over the preceding two and a half years, while cellular operators had collectively faced Rs4.5 billion in fines for regulatory violations. Officials also acknowledged that employees within mobile phone companies had been involved in leaking customer information, highlighting the difficulty of protecting data once it enters institutional systems.
One case presented to the committee demonstrated that the consequences can extend well beyond financial fraud. Officials cited an incident in Rajanpur in which a woman’s thumb impression was obtained on the pretext of providing ration assistance; her biometric information was subsequently used to obtain a SIM that was later linked to terrorist activity.
Officials have acknowledged that the existing fingerprint-based verification system is vulnerable. Interior Minister of State Talal Chaudhry described the system as “outdated” and called for facial and iris recognition, while the PTA chairman said criminals were obtaining fingerprints from places including airports, driving-licence centres and passport offices, with possible breaches extending to other identity-verification systems.
The authorities’ response, however, raises a fundamental question: should citizens be required to surrender even more sensitive information when existing safeguards have already failed? Pakistan’s expanding digital economy makes stronger monitoring and coordination among regulators, banks and telecom operators increasingly urgent, particularly as the country’s cellular subscriber base has surpassed 200 million. Measures such as immediate alerts when a SIM is issued in a citizen’s name and tighter controls linking SIMs to devices could offer additional protection, but stronger data governance must come first.
