OTP Fraud in Pakistan
OTP fraud usually involves callers or chat operators who persuade victims to read out one-time passwords, approve app prompts, or install remote-access tools. The underlying PECA analysis often involves electronic fraud or unauthorized use of identity/access credentials — not a separate “OTP section.”
Practical and legal notes
Banks repeatedly warn customers never to share OTPs. Sharing an OTP under deception can still leave a criminal investigation path against the fraudster, but it does not guarantee reversal of transfers. Preserve call details, numbers, and transaction logs.
Applicable PECA provisions
Links open LawHub’s National corpus text for PECA 2016. Read the full section before relying on a short label.
Evidence checklist
- Caller number, time, and summary of what was requested
- OTP SMS timestamps matching unauthorized transactions
- Any remote-access app install prompts or screen-share session IDs
Practical next steps
- Contact the bank fraud desk immediately.
- Secure the SIM and linked apps (SIM-swap risk).
- Compile evidence for an official cybercrime complaint if advised.
Related cybercrime topics
Find a cyber crime lawyer
Directory results only include advocates who self-reported Cyber Crime & Online Fraud (or the broader Cyber / Technology Law tag). LawHub never infers specialization from names, bios, or cities.
Sources & provenance
- The Prevention of Electronic Crimes Act, 2016 (Pakistan Code consolidation) — Ministry of Law and Justice, Government of Pakistan (Pakistan Code). National corpus consolidation_date 2025-02-07; source_id pakistancode-peca-2016.
- Prevention of Electronic Crimes (Amendment) Act, 2025 (Act No. II of 2025) — Majlis-e-Shoora (Parliament) / Senate Secretariat gazette publication. Presidential assent and Gazette Extra. publication 29 January 2025; [94(2025)/Ex. Gaz.].
- NCCIA online complaint portal — National Cyber Crime Investigation Agency (complaint.nccia.gov.pk). Host complaint.nccia.gov.pk resolves on the public DNS (Cloudflare). Bot fetches may receive HTTP 403; users should open the official domain in a browser and follow current on-site instructions.