At least six United Bank Limited (UBL) customers have reportedly lost more than Rs10 million in an alleged SIM swap fraud scheme that enabled suspects to gain access to mobile banking accounts through duplicate SIM cards. The reported losses total Rs10,458,500 and have raised concerns regarding the security of confidential banking information, SIM replacement procedures, and customer data protection. According to court records, the alleged scheme involved obtaining sensitive customer banking information, blocking customers’ original SIM cards, and activating duplicate SIMs to take control of mobile banking accounts before transferring funds. In a consolidated order dated June 17, 2026, Justice Tariq Saleem Sheikh rejected the post arrest bail application of Muhammad Atif, a UBL Branch Services Supervisor accused of disclosing customer information, while granting bail to Muhammad Usman, who is linked to the telecom franchise where the duplicate SIM cards were reportedly issued. The case originated after PTA submitted a complaint to National Cyber Crime Investigation Agency (NCCIA) in Lahore following reports from UBL customers Sultan Masood Malik and Shabbir Hussain that duplicate SIM cards had been issued against their Computerized National Identity Cards and later used to access their bank accounts without authorization.
According to the investigation, PTA traced the duplicate SIM card issued for Sultan Masood Malik on November 9, 2025, to a transfer of Rs555,000, while another duplicate SIM activated for Shabbir Hussain on November 6, 2025, was linked to a transfer of Rs422,500. Investigators connected both SIM activations to Jazz Franchise ID 6561 operating as Fine Telecom in Yazman and to a Biometric Verification System device identified by IMEI number 867332036305067. NCCIA registered FIR No. 316/2025 on November 18, 2025, under Prevention of Electronic Crimes Act 2016 together with multiple provisions of Pakistan Penal Code relating to forgery, fraud, and later criminal breach of trust under Section 409. During a joint operation carried out by NCCIA and PTA at the Fine Telecom franchise on the same day, investigators recovered two SIM scanners, one Biometric Verification System device, one central processing unit, one laptop, and approximately 150 SIM cards described as suspicious. Muhammad Usman was taken into custody during the operation together with two other individuals who were later granted bail by the trial court. As the investigation progressed, authorities identified four additional victims, bringing the confirmed financial losses to more than Rs10.45 million across six customer accounts.
Court documents also reference two internal reports prepared by UBL Fraud Risk Management Division, which indicated possible unauthorized access to confidential customer information from within the bank. The reports allegedly identified access logs showing unusual staff activity involving customer records, including registered mobile numbers. Investigators named Muhammad Atif, who served as Branch Services Supervisor at the UBL District Courts Jhang branch, after alleging that he accessed customer records through the bank Customer Relationship System and disclosed registered mobile numbers at the request of an Omni services employee, who is alleged to have passed the information to another individual involved in the investigation. According to the court order, Muhammad Atif stated that he had only been verifying customer contact numbers, but the court found that explanation lacked a reasonable basis in light of the available evidence. Justice Tariq Saleem Sheikh also examined Section 27(2) of Prevention of Electronic Crimes Act, which extends the definition of property in property related offences to include information systems and digital data. The court observed that electronic customer information can therefore fall within the scope of criminal breach of trust provisions under Pakistan Penal Code when entrusted employees are alleged to have improperly disclosed or misused confidential information.
The court also clarified that not every employee working for a financial institution automatically qualifies as a banker under Section 409 of Pakistan Penal Code. According to the ruling, this designation depends on whether the employee had actual responsibility and authority over customer account related information as part of official banking duties rather than incidental access. Applying that interpretation, the court found sufficient material at the bail stage regarding Muhammad Atif because of his supervisory responsibilities and the cumulative evidence presented during the investigation, resulting in the dismissal of his bail application. In contrast, the court found the evidence against Muhammad Usman required further examination. Although prosecutors alleged he managed the Fine Telecom franchise registered in his father’s name, the available evidence, including WhatsApp messages and an email concerning misuse of the Biometric Verification System device, was considered insufficient to establish a direct connection with the alleged SIM swap activities or the suspected disclosure of banking information. The court therefore granted him bail against surety bonds of Rs1 million while noting that the findings at the bail stage remain tentative and will not affect the outcome of the ongoing trial. The proceedings have also drawn attention to the importance of stronger biometric SIM issuance controls, telecom franchise oversight, and internal banking data security measures in addressing SIM swap related financial fraud.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.