
Loading

Loading
We use strictly necessary cookies to run this site, and analytics cookies to understand how it's used. See our Privacy Policy for details.

ISLAMABAD: The National Cyber Security Emergency Response Team (NCERT) has detected a number of suspected phishing domains created in the name of key national institutions, apparently aimed at stealing sensitive information from citizens.
Summary
According to the NCERT’s Threat Intelligence Centre, suspicious domains impersonating several government and public sector organisations were found active on Sunday (Oct 4). The identified domains include a suspected “secure login” domain impersonating the National Database and Registration Authority (Nadra), while phishing domains using names like the Federal Board of Revenue (FBR), the Higher Education Commission (HEC), the Pakistan Telecommunication Authority (PTA) and the Federal Investigation Agency (FIA) were also detected. Likewise, suspicious domains impersonating the Securities and Exchange Commission of Pakistan (SECP), the Benazir Income Support Programme (BISP) and the Prime Minister’s Youth Programme were identified.
NCERT advises public not to share personal information on unauthorised websites The Threat Intelligence Centre also spotted a suspicious login domain using the name of Punjab Safe Cities. The NCERT said the suspected phishing domains were still active and their activities were being monitored. It warned that phishing websites and impersonation-based attacks could be used to deceive users into entering sensitive information, including login credentials and other personal data.
The NCERT advised citizens and government organisations to exercise caution while accessing links, websites and login pages received through unverified sources. It urged users to verify the authenticity of websites before entering personal information and said monitoring of phishing activities and impersonation of national institutions was in progress. Safe use of GenAI At the same time, National Cert has issued an advisory for “safe and secure use of Generative Artificial Intelligence (GenAI) tools and platforms”.
The rapid adoption of public AI chatbots, coding assistants, browser extensions, AI-enabled applications, and third-party AI services is creating new cybersecurity and data governance risks across organisations, the agency observed. It added that uncontrolled or unauthorised use of Generative AI, commonly referred to as Shadow AI, may expose sensitive information, intellectual property, credentials, source code, and organisational data while introducing risks from prompt injection, insecure AI-generated code, malicious integrations, inaccurate outputs, and compromised third-party models. The NCERT has advised organisations to protect “sensitive and classified information, strictly prohibit the submission of classified, confidential, sensitive, personal, proprietary, credential-related, or otherwise restricted organisational information to public or unapproved AI platforms.
Organisations have been directed to establish an approved AI tool registry, while maintaining a centrally vetted and regularly reviewed inventory of authorised AI tools, models, browser extensions, plug-ins, APIs, and platforms. The advice added that organisations should remain on the vigil for sensitive data exposure, Shadow AI, unauthorised AI plug-ins, suspicious AI access and policy violations. The cybersecurity agency added that wherever an AI-related incident occurs, organisations should immediately contain unauthorised access.
Organisations were also advised to preserve evidence and logs, revoke compromised credentials or API keys, investigate exposure, implement corrective measures and report the incident to the NCERT.
KazaSec's take
Phishing and credential-based attacks succeed because they target people, not just infrastructure, technical controls like SPF, DKIM, and DMARC only ever close part of that gap. The rest comes down to whether a team can actually spot the fake, and whether a compromised credential can still be reused anywhere else.
Coverage details
We've archived 6 other articles touching the same topic (pakistan) , see the full security news archive.
Related security advisories
Relevant from KazaSec
More coverage on this topic
We help organizations find and fix the gaps before they make headlines.