A sophisticated cyber fraud targeting UBL customers was reported, showing how stolen banking data and fraudulent duplicate SIMs were allegedly used to bypass security safeguards and transfer more than Rs10 crore from six bank accounts.
Advocate Rizwan Abid told Daily Pakistan that the case came before Lahore High Court as two accused sought post-arrest bail in an NCCIA case involving alleged SIM swapping digital banking fraud and the unauthorized use of confidential customer information.
As per the court’s written order, two victims initially reported losing hundreds of thousands of rupees after their original SIMs were allegedly blocked and duplicate SIMs were issued against their identities.
One victim, Sultan Masood Malik, reportedly lost half million after a duplicate SIM was issued on November 9 2025. Another victim Shabbir Hussain allegedly had over Rs4Lac transferred from his account after a duplicate SIM was issued three days earlier. According to the PTA complaint cited by the court both duplicate SIMs were linked to Jazz Franchise ID 6561 operating as Fine Telecom in Bahawalpur Road Yazman.
NCCIA, PTA raided Fine Telecom in November 2025 after getting search warrant. Investigators seized two SIM scanners one BVS device one CPU one laptop and around 150 suspicious SIM cards along with mobile phones.
The investigation subsequently identified four more affected account holders taking the total number of victims to six. Authorities alleged that a combined Rs10,458,500 was fraudulently transferred from their UBL accounts.
The prosecution’s case describes organized chain in which customer information was allegedly obtained from inside the banking system before the victims’ mobile connections were targeted. Investigators alleged that confidential customer information including registered mobile numbers and banking details was accessed by insiders and passed to other members of the network.
The victims’ original SIMs were then allegedly blocked before duplicate SIMs were activated through the biometric verification system. PTA’s counsel told the court that safeguards designed to prevent fraudulent SIM issuance were allegedly circumvented through manipulation of a BVS device including claims that it was operated at reduced frequency or used with paper fingerprints through a VPN.
Once the duplicate SIM became active the alleged fraudsters could place it in another phone install or activate the bank’s mobile banking application and gain access to the victim’s account. Funds were then allegedly transferred to beneficiary accounts controlled by the perpetrators.




