The National Cyber Security Emergency Response Team (NCERT) has detected several suspected phishing domains impersonating major Pakistani government and public-sector institutions, warning citizens to remain cautious while accessing websites and online login pages.
According to NCERT’s Threat Intelligence Centre, suspicious domains impersonating organisations including the National Database and Registration Authority (Nadra), Federal Board of Revenue (FBR), Higher Education Commission (HEC), Pakistan Telecommunication Authority (PTA) and Federal Investigation Agency (FIA) were found active on October 4.
Other suspected phishing websites were identified using the names of the Securities and Exchange Commission of Pakistan (SECP), Benazir Income Support Programme (BISP), Prime Minister’s Youth Programme and Punjab Safe Cities. One of the detected domains reportedly used a “secure login” format to impersonate Nadra.
NCERT warned that such phishing websites can be designed to trick users into submitting sensitive information, including login credentials, personal details and other confidential data. Citizens have been advised to verify website addresses and avoid entering information on links received through unverified sources.
The cybersecurity agency also issued an advisory regarding the safe use of Generative Artificial Intelligence (GenAI) tools. It warned organisations about the growing risks associated with unauthorised AI platforms, browser extensions, coding assistants and third-party AI services.
NCERT highlighted the threat of “Shadow AI”, where employees or organisations use AI tools without proper approval. Such practices could expose sensitive information, credentials, source code, intellectual property and other organisational data.
Organisations have been advised to maintain approved AI tool registries, prevent sensitive or classified information from being uploaded to unapproved platforms, monitor unauthorised AI access and respond quickly to cybersecurity incidents.
NCERT further recommended preserving evidence and system logs, revoking compromised credentials or API keys, investigating potential data exposure and reporting relevant incidents to the cybersecurity authorities.
The latest warning highlights the growing need for stronger cybersecurity awareness as phishing attacks and AI-related security risks continue to increase.
Phishing Domains Impersonating Govt Agencies Detected, NCERT Issues Warning

