Latest Technology News, Gadget Reviews & Tech Updates | Gadgets About

collapse
...
Home / News / NCCIA Arrests Soneri Bank Manager Over Alleged Sale of Customer Data

NCCIA Arrests Soneri Bank Manager Over Alleged Sale of Customer Data

Oct 10, 2026  Chaudhry Arslan  5 views

NCCIA Arrests Soneri Bank Manager Over Alleged Sale of Customer Data

Pakistan's National Cyber Crime Investigation Agency (NCCIA) has arrested an operations manager of Soneri Bank over allegations that he misused access to a citizen identity-verification system and supplied sensitive personal information to people allegedly involved in online fraud.

The suspect, identified as Irfan Ashraf, was reportedly working as an operations manager at a Soneri Bank branch in Arifwala, Punjab. According to preliminary information shared by NCCIA officials, investigators believe he used his authorized access to the NADRA Verisys system to obtain citizens' identity records and allegedly provided them to fraudsters in exchange for money.

The investigation is ongoing, and the allegations have not yet been established in court.

NCCIA Finds Thousands of Identity Records

According to the NCCIA, a technical examination of the suspect's mobile phone reportedly uncovered WhatsApp conversations containing thousands of Verisys records belonging to Pakistani citizens.

Investigators are now working to determine who received the information, how it was allegedly used, and whether additional people were involved in the suspected operation. Authorities are also examining financial transactions connected to the alleged data sales.

The discovery has raised serious concerns about the potential misuse of authorized access to sensitive identity-verification systems.

Suspect Allegedly Used NADRA Verisys Access

Banks and other authorized organizations use identity-verification services to confirm customer information during legitimate transactions.

According to preliminary findings, Ashraf allegedly used his legitimate access to retrieve citizens' information outside its authorized purpose.

The NCCIA said the suspect allegedly started the activity after responding to a Facebook advertisement for a verification officer position. Investigators believe he subsequently began supplying identity information to individuals allegedly connected to online fraud.

Authorities are investigating the circumstances surrounding the alleged recruitment and identifying the people who may have requested or purchased the information.

Payments Were Reportedly Made Through JazzCash

Investigators reportedly found that the suspect did not meet the alleged recipients of the information in person.

Instead, payments were allegedly made through JazzCash. According to the NCCIA's preliminary account, the payments were routed through a mobile wallet registered in the name of an elderly person.

Authorities are investigating the wallet holder as well as the individuals who allegedly sent the payments.

Tracing these transactions could help investigators identify other people connected to the suspected data-selling network.

Elderly and Deceased Citizens Among the Alleged Records

One particularly concerning detail from the investigation is that the suspect allegedly obtained information relating primarily to elderly and deceased citizens.

The NCCIA is examining why these records were allegedly targeted and how they may have been used by people receiving the information.

Personal identity information can potentially be misused for impersonation, fraudulent account creation, unauthorized financial activity, or other forms of cybercrime. However, investigators have not yet publicly established the full extent of any harm caused in this particular case.

Reports Mention Rs150 Per Record

Some media reports have published more specific claims about the alleged operation, including an amount of approximately Rs150 per identity record and more than 100 records allegedly supplied each day.

Other reports have cited figures of around 130 records per day and estimated daily earnings of Rs12,000 to Rs15,000.

However, these specific figures have not been confirmed in the official account available from the Associated Press of Pakistan, which only states that the suspect allegedly received a few hundred rupees per record.

Therefore, the exact number of records allegedly sold and the amount of money involved should be treated as unverified until investigators provide additional evidence.

How Stolen Identity Data Can Be Dangerous

Sensitive identity information can be extremely valuable to cybercriminals.

When combined with other personal details, stolen data may potentially be used to:

  • Attempt identity theft
  • Create fraudulent accounts
  • Conduct impersonation scams
  • Target victims with personalized phishing attacks
  • Attempt unauthorized financial transactions
  • Obtain services using another person's identity
  • Facilitate other forms of online fraud

The exact ways the information was allegedly used in the Soneri Bank case remain under investigation.

The presence of identity records in the suspect's communications does not, by itself, establish that every affected person suffered financial loss.

Banking Employees Face Significant Data-Access Responsibilities

The case highlights the importance of controlling access to sensitive customer information.

Bank employees may need access to identity-verification systems as part of legitimate banking procedures. However, such access also creates significant security responsibilities.

Organizations can reduce the risk of insider misuse through measures such as:

  • Strict access controls
  • Detailed activity logging
  • Regular employee audits
  • Monitoring unusual database searches
  • Multi-level authorization
  • Automated alerts for suspicious activity
  • Regular cybersecurity training
  • Immediate investigation of abnormal access patterns

The NCCIA has reportedly indicated that it is examining other bank employees who have access to NADRA verification facilities.

Soneri Bank Warns Customers About Data Scams

Soneri Bank already advises customers not to share sensitive information such as CNIC numbers, account information, passwords, OTPs, card numbers, PINs, and CVV details with unknown callers or suspicious contacts.

The bank also states that it does not ask customers for internet or mobile banking passwords or personal information through suspicious calls or messages.

Customers should remain cautious even if a caller appears to know some personal information. Criminals can use previously obtained details to make fraudulent calls appear more convincing.

nccia-arrests-soneri-bank-operations-manager-over-alleged-sale-of-customer-data-techjuice-257344


 

What Customers Should Do

If you are concerned that your personal or banking information may have been exposed, consider taking several precautions.

Monitor Your Bank Accounts

Regularly check account activity and immediately report transactions you do not recognize.

Protect Your OTPs

Never share one-time passwords with callers, even if they claim to be bank employees or government officials.

Be Careful With CNIC Information

Avoid sending CNIC images or personal information to unknown individuals or unverified online services.

Watch for Suspicious Calls

Scammers may use personal details to convince victims that a call is legitimate. Do not assume that someone is trustworthy simply because they know your name, CNIC-related information, or bank details.

Report Suspicious Activity

If you believe your information has been misused, contact your bank and the relevant authorities as soon as possible.

Investigation Remains Ongoing

The NCCIA investigation is still underway.

Authorities are reportedly attempting to identify the people who allegedly purchased or received the information, trace the associated payments, and determine how the records may have been used.

Investigators are also examining the digital evidence recovered from the suspect's phone.

Further arrests could follow if investigators establish that additional individuals participated in the alleged network.

At this stage, the allegations against the suspect should not be treated as a final determination of guilt. The legal process and investigation will determine the facts of the case.

Final Thoughts

The arrest of a Soneri Bank operations manager over the alleged misuse and sale of citizens' identity information highlights the serious cybersecurity risks associated with privileged access to sensitive databases.

According to NCCIA's preliminary findings, the suspect allegedly used authorized access to NADRA's Verisys system and supplied citizens' identity records to people involved in online fraud. Thousands of records were reportedly found in WhatsApp conversations on his phone.

The case also demonstrates why banks, identity-verification providers, and other organizations need strong controls around sensitive customer information.

For consumers, the incident is another reminder to protect CNIC details, banking credentials, OTPs, and other personal information carefully.

As the NCCIA continues its investigation, more details may emerge about the scale of the alleged operation, the people who allegedly received the information, and whether any customers suffered financial losses.

Stay tuned to Gadgets.com.pk for the latest cybersecurity news, Pakistan technology updates, online fraud alerts, and digital privacy stories.


Share:

Leave a comment

Your email address will not be published. Required fields are marked *