Latest Technology News, Gadget Reviews & Tech Updates | Gadgets About

collapse
...
Home / Cybersecurity / Over 70 Held as NCCIA Raids Two PECHS Call Centres Over Alleged US Credit Card Scam

Over 70 Held as NCCIA Raids Two PECHS Call Centres Over Alleged US Credit Card Scam

Sep 28, 2026  Chaudhry Arslan  92 views

Two ordinary-looking buildings in a Karachi residential neighborhood have become the centre of one of the larger cyber fraud cases reported this year. The National Cyber Crime Investigation Agency (NCCIA) says it arrested more than 70 people in two raids on call centres in PECHS, both run by the same organization.

The NCCIA call centre raids took place on Sunday. The agency alleges the staff targeted US citizens with false offers of new credit cards and low-interest financial services.

 

What the agency says it found

An NCCIA spokesperson said the two premises were operated by one organization. The agency registered two cases and nominated 79 people, 48 in one and 31 in the other.

The call centres worked from residential areas, the spokesperson said, which made it hard to tell that operations were running from those addresses. The agency has not named the organization.

 

A live customer relationship management (CRM) system was seized, which the agency called a significant breakthrough. A CRM is software that stores customer records and tracks contact with them. Here, the agency says it was built for the purpose and was used to hold detailed information on the US-based people who were targeted.

How the alleged scheme worked

The FIRs describe a chain of steps. According to the interrogation findings quoted in them, agents obtained Social Security Numbers, phone numbers, dates of birth, and bank and credit card details. They allegedly did so by posing as authorized representatives of regulated US financial institutions.

 

The details were then passed to the call centre owners through the local, server-based CRM. The owners, the FIRs say, shared them with merchants managed by their partners, who used them to make unauthorized charges.

That description places the fraud in two stages. The first was the phone call. The second was the payment, where stolen card data was turned into charges through merchant accounts.

The charges

The suspects have been booked under the Prevention of Electronic Crimes Act (Peca) and the Pakistan Penal Code (PPC). The FIRs were registered at the Cyber Crime Reporting Centre police station on the complaint of NCCIA Inspector Muhammad Ali.

Under Peca, the sections cited cover unauthorized access to an information system or data, unauthorized copying or transmission of data, and unauthorized access to critical infrastructure information. They also cover electronic forgery, electronic fraud, unauthorized use of identity information, and spoofing. The PPC sections are abetment and common intention.

These are allegations at the FIR stage. Nominating a person in a case is not the same as proving guilt, and no court findings have been reported.

Why the CRM matters more than the arrests

The agency has said the seized computers, CRM, and data are secured and going through forensic examination. It expects the material to show the network, the customer database, the chain of command, and the way the operation worked.

That is where the case may widen. If the CRM records link agents to owners and owners to merchants, investigators could trace the money side of the operation, not just the phone room. The FIR text already points to merchants managed by the owners’ partners, and those people were not described as arrested.

Software of this kind also keeps a record of what was done and when. Fraud operations that run on a shared system leave a trail that a cash-based scheme would not.

The cost to Pakistan’s legitimate call centre sector

Pakistan’s outsourcing industry has grown in recent years. IT and IT-enabled services exports reached a record $4.6 billion in FY2025-26, according to State Bank of Pakistan data reported by local media, and call centres are one part of that mix.

Cases like this one put pressure on that reputation. A foreign client choosing a vendor in Pakistan has little way of telling a legitimate business process outsourcing (BPO) firm from a fraudulent one, and each raid adds to the doubt. The firms that follow the rules are the ones that pay for it in lost trust.

The residential setting raises a practical question for regulators. If a call centre can run from an ordinary house without drawing attention, then registration and inspection systems may not be reaching the people who most need to be checked. The agency’s statement does not say whether the organization was registered with anybody.


Share:

Leave a comment

Your email address will not be published. Required fields are marked *

Your experience on this site will be improved by allowing cookies Cookie Policy