LAHORE – A manager of Soneri Bank has been arrested for allegedly selling thousands of Pakistanis’ sensitive NADRA identity records to online fraudsters for a few hundred rupees per record, with investigators reportedly recovering extensive data from his mobile phone.
National Cyber Crime Investigation Agency (NCCIA) shared details of the arrest as the bank insider turned access to Pakistanis’ sensitive identity records into source of illegal income, selling information obtained through NADRA’s verification system to online fraudsters.
NCCIA Lahore Zone arrested operations manager Irfan Ashraf, and recovered WhatsApp conversations containing thousands of citizens’ identity records from his mobile phone, raising questions about the scale of alleged data-selling operation. NCCIA Lahore Zone Additional Director Atif Ameer confirmed the arrest and preliminary findings. The suspect was reportedly employed at a bank branch in Arifwala, Punjab.
According to preliminary investigation, the suspect allegedly used his authorised access to NADRA’s Verisys identity verification system to retrieve citizens’ records and supply them to people involved in online fraud. The alleged operation reportedly began after he spotted a Facebook advertisement offering a job as a verification officer. Investigators believe he subsequently connected with buyers remotely and received payments through JazzCash.
The money was reportedly transferred through a mobile wallet registered in the name of an elderly person. Investigators are now examining the account holder’s role and tracing the individuals who allegedly purchased the information.
Official reporting puts the payment at a few hundred rupees per record. Secondary reports have gone further, claiming that the suspect sold around 130 records daily for Rs150 each and earned between Rs12,000 and Rs15,000 a day. These figures have not been confirmed by the available official account.
Investigators are trying to establish how the information was used and whether it enabled identity theft, fraudulent banking activity or other financial crimes. The data was used to create fraudulent or parking accounts to move illicit funds. However, the precise method has not been confirmed in the official reporting available so far.
The discovery of thousands of records in WhatsApp conversations has also raised questions about whether the alleged operation involved multiple buyers or formed part of a wider data-trading network. The investigation is continuing, and the full extent of the alleged activity remains unclear.
Earlier, a case involving United Bank Limited (UBL) surfaced online, where a branch services supervisor identified in reports as Muhammad Atif faced allegations of disclosing customers’ registered mobile numbers. The case was linked to alleged SIM-swap fraud, unauthorised access to mobile banking and transfers exceeding Rs10.45 million from six accounts.
A Jazz franchise operator was also reportedly implicated in the issuance of duplicate SIM cards. The Lahore High Court proceedings highlighted the potential criminal consequences of misusing access to confidential customer information.
The cases show how information obtained from one institution can potentially be exploited alongside weaknesses in another system, exposing customers to financial losses.
UBL Customers lose over Rs10 Crore in Shocking Data Leak, Duplicate SIM Fraud













