Phishing in Pakistan
Phishing uses fake messages or websites that imitate trusted brands to capture passwords, card data, or OTPs. Depending on the method and harm, PECA provisions on electronic fraud, identity information, or spoofing may be engaged.
Legal anchors (not a closed list)
If the phishing induces you into a deceptive electronic interaction for wrongful gain, section 14 is commonly discussed. Harvesting or using identity credentials without authorization may engage section 16. Spoofed sender identities are addressed in section 26. Exact charges are for investigators and courts.
Applicable PECA provisions
Links open LawHub’s National corpus text for PECA 2016. Read the full section before relying on a short label.
Evidence checklist
- Original phishing SMS/email with full headers where available
- URL of the fake page and screenshot of the login form
- Any credentials you entered and the time of entry (change passwords afterward)
- Resulting unauthorized transactions
Practical next steps
- Change passwords and enable MFA on affected accounts.
- Alert your bank/wallet.
- Preserve the phishing artefact, then consider an official complaint.
Related cybercrime topics
Find a cyber crime lawyer
Directory results only include advocates who self-reported Cyber Crime & Online Fraud (or the broader Cyber / Technology Law tag). LawHub never infers specialization from names, bios, or cities.
Sources & provenance
- The Prevention of Electronic Crimes Act, 2016 (Pakistan Code consolidation) — Ministry of Law and Justice, Government of Pakistan (Pakistan Code). National corpus consolidation_date 2025-02-07; source_id pakistancode-peca-2016.
- Prevention of Electronic Crimes (Amendment) Act, 2025 (Act No. II of 2025) — Majlis-e-Shoora (Parliament) / Senate Secretariat gazette publication. Presidential assent and Gazette Extra. publication 29 January 2025; [94(2025)/Ex. Gaz.].
- NCCIA online complaint portal — National Cyber Crime Investigation Agency (complaint.nccia.gov.pk). Host complaint.nccia.gov.pk resolves on the public DNS (Cloudflare). Bot fetches may receive HTTP 403; users should open the official domain in a browser and follow current on-site instructions.