National CERT Warning: Fake Government Websites Target Pakistanis

National CERT Warning

Pakistan’s National Cyber Emergency Response Team (National CERT) has issued a National CERT warning about several fake websites impersonating major government and public-sector institutions. The malicious websites reportedly target users of organisations including NADRA, FBR and HEC, with the apparent goal of stealing login credentials and other sensitive information.

Fake Websites Target Trusted Institutions

The National CERT Threat Intelligence Centre identified several suspicious domains that were active and designed to resemble legitimate government services. One of the highlighted domains, secure-login-nadra.com, was identified as targeting NADRA users for credential theft.

Other suspicious websites were found using the names of the Federal Board of Revenue and Higher Education Commission. The campaign reportedly extended to several other institutions, including the Pakistan Telecommunication Authority, Federal Investigation Agency, Directorate General Immigration & Passports and Securities and Exchange Commission of Pakistan.

The use of well-known government names can make these websites appear trustworthy to ordinary users. Attackers can then attempt to persuade visitors to enter usernames, passwords, identification details or other confidential information.

Threat Scores Raise Concern

The National CERT warning comes after its monitoring system identified a number of these domains as active threats. The reported threat scores ranged from 87 to 99 percent, indicating a high level of concern associated with the identified websites.

Another suspicious domain, secure-login-punjabsafecities.com, was reportedly found impersonating Punjab Safe Cities and targeting users for credential theft. The monitoring platform also listed suspicious domains associated with the Benazir Income Support Programme and Prime Minister’s Youth Programme.

According to the monitoring information, several of the domains were registered through NameCheap. The use of domain names containing familiar institutional names appears intended to make fraudulent pages look more credible to visitors.

How Phishing Websites Work

Phishing websites are designed to imitate legitimate online services. A user may receive a link through an email, text message, social media post or another online platform and be encouraged to sign in or provide information.

Once a victim enters details on a fraudulent page, those credentials may be captured by attackers. The information can potentially be used for account compromise, identity theft or further fraud.

The Federal Board of Revenue has previously warned taxpayers about fraudulent emails and websites that imitate official FBR services. It advises users not to provide passwords, banking information or other sensitive details through suspicious links.

The Higher Education Commission has also warned the public about fraudulent websites claiming to be associated with HEC. The commission states that users should rely on its official online service portal and avoid unauthorized websites requesting personal information, passwords or financial details.

National CERT Urges Public to Stay Alert

The latest National CERT warning highlights the importance of checking a website carefully before entering any personal information. Users should not assume that a website is legitimate simply because it displays a government logo or uses familiar institutional names.

People should carefully inspect the domain name and avoid clicking login links received through unexpected messages. When accessing an important government service, it is safer to manually enter the institution’s known official web address or reach the service through its verified website.

National CERT itself operates an official cybersecurity platform and has introduced Phish-Radar to help users verify suspicious URLs, report phishing websites and improve awareness of online threats.

Protecting Personal Information Online

Citizens should avoid entering passwords, CNIC details, banking information, OTPs or other sensitive data on unfamiliar websites. A website that creates unnecessary urgency, demands confidential information or uses a suspicious domain should be treated with caution.

Users who believe they have entered information into a phishing website should take immediate steps to secure the affected account, including changing compromised passwords and monitoring accounts for unusual activity.

The National CERT warning serves as a reminder that cybercriminals increasingly exploit public trust in government institutions. As more government services move online, citizens need to verify digital platforms before sharing information.

For Pakistan’s growing digital ecosystem, awareness remains an important part of cybersecurity. Checking web addresses, avoiding suspicious links and using official government portals can significantly reduce the risk of falling victim to phishing campaigns.