Menu

Phishing Websites Impersonate Government Agencies

Phishing Websites Impersonate Government Agencies

Pakistan’s National Cyber Security Emergency Response Team (NCERT) has detected several suspected phishing domains impersonating major government and public-sector institutions, raising concerns over attempts to steal sensitive information from citizens.

According to the NCERT Threat Intelligence Centre, suspicious websites posing as official platforms of institutions including the National Database and Registration Authority (NADRA), Federal Board of Revenue (FBR), Higher Education Commission (HEC), Pakistan Telecommunication Authority (PTA) and Federal Investigation Agency (FIA) were found active on October 4.

Other suspected phishing domains were identified using the names of the Securities and Exchange Commission of Pakistan (SECP), Benazir Income Support Programme (BISP), Prime Minister’s Youth Programme and Punjab Safe Cities. One of the detected websites reportedly used a “secure login” format designed to appear legitimate.

NCERT warned that such impersonation-based attacks could trick users into submitting login credentials, personal details and other sensitive information. The agency urged citizens to verify website addresses and avoid entering personal information on links or login pages received through unverified sources.

The cybersecurity agency said the suspected domains remained under monitoring and advised government organisations and the public to exercise caution when accessing online services.

NCERT Warns Against Shadow AI Risks

In a separate advisory, NCERT also highlighted cybersecurity and data-governance risks associated with the growing use of generative artificial intelligence (GenAI) tools.

The agency warned that unauthorised use of public AI chatbots, coding assistants, browser extensions, AI applications and third-party services — commonly referred to as “Shadow AI” — could expose sensitive data, intellectual property, credentials, source code and other organisational information.

NCERT also identified risks including prompt injection, insecure AI-generated code, malicious integrations, inaccurate AI outputs and compromised third-party models.

Organisations have been advised to prohibit employees from entering classified, confidential, personal, proprietary or credential-related information into public or unapproved AI platforms. They have also been encouraged to establish an approved AI tool registry covering authorised AI platforms, models, browser extensions, plug-ins and APIs.

The advisory further recommends monitoring for unauthorised AI usage and sensitive data exposure. In the event of an AI-related security incident, organisations should contain unauthorised access, preserve evidence and logs, revoke compromised credentials or API keys, investigate potential exposure, implement corrective measures and report incidents to NCERT.