A growing number of fake websites are impersonating Pakistani government institutions and targeting users for sensitive information.
The National CERT has warned citizens about several fraudulent websites posing as trusted government and public-sector organisations. These websites appear designed to steal login credentials and other sensitive user data.
The warning follows the detection of active websites impersonating institutions including NADRA, the Federal Board of Revenue and the Higher Education Commission.
Fake Websites Pose as Government Institutions
The National CERT Threat Intelligence Centre identified several suspicious websites during its monitoring activities.
One such website, secure-login-nadra.com, was detected on October 4 while targeting NADRA users for credential theft.
Similar websites were also found impersonating the FBR and HEC. However, the campaign extends beyond these three institutions.
National CERT also identified phishing websites using the names of several other Pakistani public organisations.
These include the Pakistan Telecommunication Authority, Federal Investigation Agency, Directorate General Immigration & Passports and Securities and Exchange Commission of Pakistan.
The list also includes the Benazir Income Support Programme and Prime Minister’s Youth Programme.
Suspicious Websites Carry High Threat Scores
The identified websites have been classified as active threats on the National CERT monitoring platform.
Their threat scores ranged from 87 to 99 percent, highlighting the seriousness of the detected activity.
Another suspicious domain, secure-login-punjabsafecities.com, was also found impersonating Punjab Safe Cities. The website was reportedly targeting users for credential theft.
Meanwhile, the monitoring platform showed that the suspicious domains remained active. The listed websites were registered through NameCheap Inc., according to the available information.
Citizens Urged to Check Websites Carefully
National CERT is continuing to monitor phishing and impersonation attempts targeting organisations in Pakistan and abroad.
Therefore, citizens have been advised to exercise particular caution when opening links connected with government services.
Users should carefully verify a website before entering passwords, account details or other sensitive information.
They should also avoid submitting login credentials through suspicious or unverified platforms.
Government Website Impersonation Raises Data Security Concerns
The latest warning highlights how fraudulent websites can use the names of trusted public institutions to appear legitimate.
As these websites imitate familiar government organisations, users may be more likely to trust their login pages. Consequently, checking the website address before entering personal information remains important.
The detected websites are not limited to one government department or public service. Instead, the campaign has targeted multiple institutions, including those handling identity records, taxation, education and public assistance.
National CERT continues to monitor the activity as suspicious websites remain active. For users, the warning is clear: government-related login pages should be verified carefully before any sensitive information is submitted.
For the latest updates, visit and follow The Truth International website (www.thetruthinternational.com) and subscribe to the YouTube Channel.
