Top 5 This Week

spot_img

Related Posts

NCERT Warns Citizens Against Fake Government Websites Stealing CNICs and Passwords

NCERT Warns Citizens Against Fake Government Websites Stealing CNICs and Passwords

NCERT Warns Citizens Against Fake Government Websites Stealing CNICs and Passwords

Pakistan’s National Cyber Emergency Response Team has issued a critical alert about fake government websites impersonating state institutions to steal citizens’ personal data, urging the public to check web addresses carefully before entering any credentials.

The alert, issued on October 4 by the team’s Threat Intelligence Centre, describes a wide network of phishing domains designed to look like the official portals of NADRA, the Federal Board of Revenue, the Federal Investigation Agency, the Pakistan Telecommunication Authority, the Higher Education Commission, the Securities and Exchange Commission of Pakistan, the Benazir Income Support Programme, the Prime Minister’s Youth Programme, the Punjab Safe Cities Authority and the Directorate General of Immigration & Passports.

How the fake government websites scam works

Investigators say the operators registered the domains through low-cost registrars such as NameCheap and built cloned login forms that mimic official sites. On NCERT’s threat platform, the active domains scored between 87 and 99 per cent.

The attack follows a four-step blueprint. First, phishing links arrive through SMS, WhatsApp messages or search ads, dressed up as urgent official notices. Second, the links open cloned portals that copy government logos, colours and layouts. Third, victims are asked to type in their CNIC numbers, passwords and one-time passcodes. Fourth, the stolen data is put to work — for identity theft, banking fraud, or resale to other criminals.

Spotting the fakes

NCERT says the single most reliable check is the address itself: genuine state websites end in .gov.pk. The fakes tend to use .com, .xyz or .io domains, or add suspicious prefixes such as “secure-login-” before a familiar agency name.

Other warning signs include broken navigation links, poor grammar and rushed design. And the team cautions that a padlock icon and an HTTPS address alone prove nothing — phishing sites routinely use encryption.

How to stay safe

The advisory asks citizens to reject any portal that does not end in .gov.pk, to type official addresses directly into the browser or use bookmarks, and to verify security advisories at pkcert.gov.pk before trusting a warning that arrives by text or chat. Families should be told about the scam, especially elderly relatives who may be targeted first.

Anyone who has already entered details on a suspicious site should reset their passwords immediately, alert their bank, and report the matter to the National CERT or the National Cyber Crime Investigation Agency.

Which institutions are being impersonated?

NADRA, FBR, FIA, PTA, HEC, SECP, BISP, the PM’s Youth Programme, Punjab Safe Cities Authority and the Directorate General of Immigration & Passports, among others.

How can I tell a fake site from a real one?

Real government sites end in .gov.pk. Fakes use .com, .xyz or .io addresses, add words like “secure-login-“, show broken links and poor grammar. HTTPS alone is not proof of legitimacy.

What should I do if I entered my details on a fake site?

Reset your passwords at once, inform your bank, and report the incident to the National CERT or the National Cyber Crime Investigation Agency.

Feature Pakistan
Feature Pakistan is an independent digital media platform committed to highlighting the culture, achievements, and untold stories of Pakistan.

opinion