In recent weeks, social media in Pakistan has been dominated by viral “leaks”, from the Umairi clip controversy to false AI-generated videos attributed to Alina Amir.
While these sparks grab public attention, they also underscore a much broader cybersecurity crisis in the country that goes well beyond individual reputation issues.
The Umairi viral video episode
In early January 2026, a video widely referred to online as the “Umairi 7:11” clip exploded across social media, prompting huge search traffic and debate.
Police in Gujranwala even arrested a man known as Umair Cheema and a woman allegedly shown in the footage, sparking public outrage and legal scrutiny. Critics argued the real issue was not the people on camera but the leaking and redistribution of private content without consent.
The Alina Amir deepfake controversy
In late January 2026, social media saw a surge of links claiming a leaked private video of Pakistani TikTok influencer Alina Amir was circulating. Investigations, however, showed:
The links circulated widely did not contain any authentic video but instead appeared to be clickbait leading to malware, phishing or other harmful sites.
Alina Amir publicly denied the authenticity of the alleged leak and stated the material was an AI-generated deepfake designed to harm her reputation.
She called for legal action against creators and spreaders of such AI-generated harassment content, framing it as a crime and form of “digital violence.”
Cyber threat reality: Far beyond social scandal
Pakistan is experiencing a sharp rise in digital attacks of all kinds. According to cybersecurity firm Kaspersky, over 5.3 million cyberattacks were detected in Pakistan in the first nine months of 2025, including malware infections, phishing, fake Wi-Fi traps, spyware and ransomware attempts, affecting both individuals and organizations.
Deepfake and misuse of AI: A new security frontier
The Alina Amir deepfake incident — where AI-generated videos falsely ascribed to a social media influencer spread rapidly before being publicly denied by her, highlights how malicious AI use is emerging as a cyber threat. Amir described the episode as digital violence and urged authorities to act against creators and sharers of fake content.
Experts point out that deepfake technology is becoming a serious issue in Pakistan. It enables attackers to fabricate highly convincing audiovisual content with minimal technical expertise, often aimed at defamation, harassment, or revenue through clickbait and misinformation.
Globally, a vast majority of deepfake content trending online is sexually exploitative and such content is increasingly weaponized against women in Pakistan.
Legal and institutional response: Still catching up
Pakistan’s primary legal tool against cybercrime is the Prevention of Electronic Crimes Act (PECA) 2016, intended to criminalize unauthorized data leaks, hacking, defamation, and online harassment. However, enforcement and clarity are ongoing challenges:
PECA is being revised, proposals include stronger penalties for fake or harmful content, protection of digital rights, and establishing a specialized investigative authority to tackle cybercrime more effectively.
Some local law enforcement units already register cybercrime cases involving AI-generated content and online defamation under PECA and related legal provisions.
Pakistan Telecommunication Authority (PTA) has clarified that blocking illegal content falls under its mandate, but it doesn’t extend to investigating cybercrime itself, which is why agencies like the FIA Cyber Crime Wing are crucial.
These developments indicate recognition of the problem at the policy level, but implementation and public awareness remain insufficient.
Systemic vulnerabilities: Not just social scandals
The leaks vs. deepfakes headlines also point to deeper structural cybersecurity weaknesses:
Pakistani users’ personal data has surfaced in massive global breaches, expose millions of credentials, emails, and passwords, making social media and online accounts even easier to compromise.
Cyber threats are not limited to pranks or scandals: both private citizens and state systems face sophisticated phishing, ransomware and malware campaigns regularly.





