#PKCERT
🚨 National Cyber Emergency Response Team (PKCERT) Announces Internship Program for Fresh Graduates! 🚨
.

#PKCERT #CyberSecurity #CyberInternship #InternshipOpportunity #PakistanJobs #FreshGraduates #CareerGrowth #TechCareers
June 4, 2026 at 6:59 AM
Guidelines issued for officials to prevent cyberattack
ISLAMABAD: Govern­ment employees and public-sector organisations have been warned against using personal email acco­unts, unapproved devices, commercial cloud services and public AI tools for official or sensitive government information. Titled the “National Cybersecurity Handbook 2026-27”, the document, issued by the National Cyber Emergency Resp­onse Team (PKCERT) and the Ministry of IT and Telecommunications, outlines baseline operational standards for digital security across public-sector entities. According to the handbook, cybersecurity is not solely a technical responsibility but a shared one, as every user can affect the confidentiality, integrity and availability of gov­e­rnment information assets. The handbook’s guidance on artificial intelligence highlights a growing area of cybersecurity risk. > Govt warns staff against using personal emails, devices, AI tools It says officials should not enter classified government documents, official emails, source code or citizens’ personally identifiable information into public AI platforms. Government employees are advised to use only AI tools authorised by their departments and to remove names and sensitive information from prompts or uploaded files. AI-generated outputs should also be reviewed by humans for accuracy and potential security implications. The document also warns against installing unapproved AI extensions or plugins and sharing administrative credentials, API keys or passwords with AI tools. One of the key instructions is that official email accounts must be used for government correspondence and departmental work. Personal accounts such as Gmail and Yahoo should not be used except where exceptionally authorised by the department, while official emails must not be forwarded to personal inboxes. The handbook further says official email addr­esses should not be used to register on shopping, gaming or social media websites, while mailing lists and directories should not be shared with unauthorised entities. Only authorised government devices are to be used for official work. Where a personal device is operationally necessary, prior departmental authorisation is required, and the device must meet prescribed security standards. Officials have similarly been instructed to use only sanctioned cloud services and approved applications. The handbook places particular emphasis on the early reporting of cyber incidents. These include unauthorised access atte­mpts, ransomware notes, suspicious emails, unusual deletion or modification of files and unexplained system behaviour. _Published in Dawn, September 19th, 2026_
www.dawn.com
September 19, 2026 at 4:15 AM
کراچی میں فورٹینیٹ سیکیورٹی ڈے پاکستان 2026، سائبر سیکیورٹی پر خصوصی توجہ

#اےآئیسیکیورٹیPKCERTڈیجیٹلسیکیورٹی

https://justpaste.in/news/urdu/krachy-my%da%ba-fwr%d9%b9yny%d9%b9-sykywr%d9%b9y-%da%88%db%92-pakstan-2026-saybr-sykywr%d9%b9y-pr-khswsy-twj%db%81/
کراچی میں فورٹینیٹ سیکیورٹی ڈے پاکستان 2026، سائبر سیکیورٹی پر خصوصی توجہ
justpaste.in
September 9, 2026 at 6:36 PM
>The National Cyber Emergency Response Team (PKCERT) has issued a high-priority alert, warning social media users of a significant data breach involving major platforms, including Google, Microsoft, and Facebook.

>184 million passwords confirmed
www.nation.com.pk/26-May-2025/...
PKCERT issues urgent warning following massive social media data breach
The National Cyber Emergency Response Team (PKCERT) has issued a high-priority alert, warning social media users of a significant data breach involving major
www.nation.com.pk
May 26, 2025 at 11:50 PM
PKCERT, Kaspersky sign MoU to strengthen cybersecurity in Pakistan
The Pakistan Computer Emergency Response Team (PKCERT) on Monday signed a memorandum of understanding (MoU) with global cybersecurity company Kaspersky to enhance cybersecurity in Pakistan through collaboration. PKCERT is a federal government entity responsible for protecting Pakistan’s digital assets, sensitive information, and critical infrastructure from cyberattacks, cyberterrorism, and cyber espionage. A joint press release issued on Monday said that the agreement marked a major step toward enhancing Pakistan’s national cybersecurity posture through collaboration in threat detection, mitigation, and prevention. “The partnership between PKCERT and Kaspersky focuses on strengthening the country’s cyber resilience through a series of coordinated efforts. These include extensive training and awareness programs designed to enhance operational readiness across all levels of government, industry, academia, and civil society,” the statement said. It added that the collaboration also focused on capacity development to cultivate a skilled cybersecurity workforce aligned with both national and international standards. “Additionally, the two organisations will ensure the timely dissemination of actionable cyber threat intelligence to relevant stakeholders across Pakistan,” it said. Under the MoU, the statement added, the organisations will cooperate across a wide range of cybersecurity areas, “including legislative and regulatory issues, incident detection and response, prevention and mitigation strategies, cybersecurity education, research and development, and professional exchanges”. “The two organisations will exchange relevant technical information, threat intelligence, and data feeds related to cyber threats and cyberattacks affecting citizens, businesses, and government institutions in Pakistan,” it said. According to the press release, the MoU was signed by Dr Haider Abbas, the director general of PKCERT, and Rashed Al Momani, general manager for the Middle East and Pakistan at Kaspersky. It was signed in the presence of Kaspersky CEO Eugene Kaspersky and IT Minister Shaza Fatima Khawaja. “Information and communication technologies (ICTs) play a vital role in socio-economic development of a country; however, they have also introduced new challenges such as cyber espionage, hacktivism, ransomware, data breaches, identity theft, attacks on critical infrastructure, financial and supply chain disruptions, and disinformation campaigns,“ the statement quoted Abbas as saying. “Our collaboration with Kaspersky, a global leader with expertise in these domains, represents another important step toward strengthening national cybersecurity,” he added. “Safeguarding digital development requires robust cybersecurity, founded on deep and continuous partnerships between public authorities and private companies. Kaspersky has a long and fruitful history of working with global and regional organisations such as Interpol and Afripol, as well as local computer emergency response teams around the world,” Al Momani said. “We highly value this cooperation with PKCERT as an important step in consolidating Pakistan’s secure digital transformation for the entire nation,” he added.
www.dawn.com
January 5, 2026 at 9:34 AM
Cybersecurity Act essential to national security, says IT minister
ISLAMABAD: Federal Minister for Information Technology (IT) and Telecom Shaza Fatima Khawaja said the Cybersecurity Act 2025 was essential for national security and reflected the government’s whole-of-nation approach to cybersecurity, marking a major reform initiative. She noted that the Act will establish the National Cybersecurity Authority (NCA) to lead nationwide incident response and thr­eat intelligence, while exp­ansion of the Pakistan Computer Emergency Res­ponse Team (PKCERT), and the development of secure digital public infrastructure under the Digital Economy Enhancement Project (Deep) will further strengthen national cyber resilience. Ms Khawaja was add­ressing a gathering at FAST National University, Islam­abad, on the theme ‘Securing Pakistan’s Digi­tal Frontier: CyberShield, Policy & the Future’. The event was hosted by the FAST Public Policy and Res­earch Society (FPPRS). She added that Pakis­tan’s long-term objective is to build a cyber-resilient, innovation-driven dig­ital nation where secure infrastructure, technological excellence, and human cap­ital development adva­nce together. The minister underscored that Pakistan’s digital transformation is accelerating at an unprecedented pace, bringing with it the critical responsibility of safeguarding national digital infrastructure and citizen data. She highlighted Pakistan’s Tier-1 ranking in the ITU Global Cybersecurity Index as a reflection of the collective commitment of the government, academia, and youth toward building a secure digital future. The minister said Pakistan is rapidly advancing toward AI-driven cybersecurity, dark-web moni­toring, and cloud security under the Cloud-First Policy, along with secure digital identity frameworks. She also referred to the recent Marka-i-Haq, calling it a defining moment in which the armed forces, national institutions, and cyber experts stood united with remarkable resilience. She emphasised that Pakistan’s effective and coordinated cyber warfare response during this period demonstrated exceptional national strength and technological capability, adding that Marka-i-Haq proved the cyber domain is the first line of defence in the modern era, and Pakistan has shown it can safeguard its digital frontiers with confidence and competence. The minister also toured FAST-NU Islamabad’s IC Design Lab along with Director Dr Waseem Shahzad, Dean Dr Sadia Nadeem, and Fast Public Policy and Research Society (FPPRS) President Zainab Inam Cheema, and met scholars enrolled in Ignite’s flagship training initiative, “Training in IC Design & Verification.” Under this Ignite-funded programme, 30 young engineers — including seven female participants — are undergoing a rigorous 10-month training course covering IC design, verification, and fabrication processes. Implemented by FAST-NU, the programme offers hands-on training aligned with global semiconductor industry standards. _Published in Dawn, November 29th, 2025_
www.dawn.com
November 29, 2025 at 3:28 AM
PTA denies breaches in licensed sector after reported SIM data leak
The Pakistan Telecommunication Authority (PTA) on Tuesday said its audit found no breaches in the licensed telecom sector following reports of a mobile SIM data leak. Media reports claimed that the data of all SIM holders, including Interior Minister Naqvi, was up for sale, with mobile location information priced at Rs500, call and data records at Rs2,000, and details of foreign trips at Rs5,000. A couple of months ago, the National Cyber Emer­gency Response Team of Pakistan (PKCERT) iss­ued an advisory warning that the login credentials and passwords of more than 180 million internet users in Pakistan were stolen in a global data breach, urging people to take immediate protective measures. Media reports said PKCERT had identified the global breach involving a publicly accessible, unencrypted file containing more than 184m unique account credentials. Responding to the matter today, the PTA said it had taken notice of the media reports on the alleged availability of subscriber data online. “PTA clarifies it does not hold or manage subscriber data, which remains solely with licensed operators. “Initial review shows the reported datasets include family details, travel records, vehicle registrations, and CNIC copies, indicating aggregation from multiple external sources, not telecom operators. PTA’s audits have found no breaches within the licensed sector,” the authority said. It added that in its ongoing crackdown on unlawful content, it had blocked 1,372 sites, apps and social media pages involved in selling or sharing personal data. The PTA pointed out that the Ministry of Interior has already formed an inquiry committee, which is probing into the matter. In March 2024, a joint investigation team formed to probe a data leak from the National Database and Registr­ation Authority told the interior ministry that the credentials of as many as 2.7m people had been compromised between 2019 and 2023.
www.dawn.com
September 9, 2025 at 1:28 PM
Data protection standards issued for companies to safeguard citizens’ personal information
The National Cyber Emergency Services Response Team (PKCERT) on Wednesday issued data protection guidelines for organisations handling citizens’ personal information, citing an increasingly insecure cyberspace environment. PKCERT is a federal entity responsible for protecting Pakistan’s digital assets, sensitive information and critical infrastructure from cyberattacks, cyberterrorism, and cyber espionage. The advisory, applicable to companies holding Personally Identifiable Information (PII), prescribes immediate, medium- and long-term measures, which include classifying data sets based on their sensitivity, advanced encryption methods, multi-factor authentication, and others. Organisations collecting, processing, storing, or transmitting PII may include “financial services, telecommunications and internet providers, commerce and logistics [companies], government agencies, healthcare institutions, educational entities, as well as third-party and outsourced service providers,” the notification said. In its recommendations, PKCERT instructed companies to keep their PII handling systems updated, retain PII only for legally required durations, and dispose of outdated information lest it be stolen. It also urged organisations to align their practices with the National Cyber Security Policy 2021 (NCSP) as well as the Prevention of Electronic Crimes Act 2016. The NCSP “mandates safeguarding the confidentiality, integrity, and availability of citizens’ personal data as a matter of national security and public trust,” reads the advisory. PKCERT also called for an immediate review of the systems organisations have been using to handle PII, recommended security training for all staff handling personal information, as well as continuous monitoring to prevent unauthorised access. Recomendations made by the PKCERT advisory. Outlining possible vulnerabilities and threats, the cybersecurity body underscored the need for data protection, noting that in light of “the growing sophistication of cybercriminals, the widespread exploitation of misconfigured systems, and negligent data handling practices, urgent remediation measures are required.” The advisory detailed that threat actors may include: * **Cybercriminal Gangs** : Monetising stolen PII via identity fraud, phishing kits, and dark web marketplaces. * **State-Sponsored APT Groups:** Using compromised citizen data for surveillance, political manipulation, and intelligence gathering. * **Hacktivists:** Targeting organisations for ideological reasons, often leaking sensitive records publicly. * **Malicious Insiders:** Employees or contractors exploiting privileged access for personal gain or revenge. According to PKCERT, inadequate data protection can lead to “identity theft, fraud, mass privacy breaches, operational disruption, erosion of public trust, national security risks and legal and regulatory consequences.” In its recommendations to individuals, the advisory outlined preventative measures such as submitting CNIC and personal documents only when necessary, using strong passwords, enabling multi-factor authentication, and avoiding sharing personal information online. In May, PKCERT issued an advisory warning that the login credentials and passwords of more than 180 million internet users in Pakistan had been stolen in a global data breach, and urged citizens to take immediate protective measures. In March 2024, a Joint Investiga­tion Team (JIT) formed to probe a data leak from the National Database and Registration Authority (Nadra) had found that the credentials of as many as 2.7 million citizens had been compromised between 2019 and 2023.
www.dawn.com
August 20, 2025 at 12:16 PM
Cybersecurity body urges cautious use of social media
ISLAMABAD: The national cybersecurity authority has urged citizens to use social media responsibly and remain vigilant against cyber threats. The advisory issued by the National Computer Emergency Response Team (PKCERT) highlighted risks like disinformation, fraud, harassment, invasion of privacy and data breach. The PKCERT flagged the increase in cyber incidents affecting children, including exposure to explicit content and online grooming. Women are “frequently targeted” with cyber harassment, identity theft and image-based abuse, risks that are “compounded by broader societal inequities”. The advisory cautioned that many social media posts are “deliberately designed to provoke strong emotions—such as anger, fear, or shock—prompting users to react or share them quickly without giving the content much thought”. It added that social media platforms use algorithms to display content that triggers intense emotional reactions. “This approach keeps users engaged for longer periods, even if the information is not always accurate or beneficial.” To counter these risks, the advisory suggested strong, unique passwords with multi-factor authentication. Social media users should not share their real-time location and regularly update the apps. To counter propaganda, users must cross-check information mentioned in social media posts and remain “sceptical of viral trends”. _Published in Dawn, June 6th, 2025_
www.dawn.com
June 6, 2025 at 7:17 AM
Over 180m users’ passwords, login credentials stolen in massive data breach, says national cyber security body
The National Cyber Emergency Response Team (PKCERT) on Monday issued an advisory warning that the login credentials and passwords of more than 180 million internet users in Pakistan have been stolen in a global data breach, urging people to take immediate protective measures. According to the advisory, seen by _Dawn.com_ , PKCERT identified the global breach involving a publicly accessible, unencrypted file containing more than 184 million unique account credentials. “The breach exposed usernames, passwords, emails and associated URLs tied to services from Google, Microsoft, Apple, Facebook, Instagram [and] Snapchat, as well as government portals, banking institutions, and healthcare platforms worldwide,” the advisory read. “The leaked database is believed to have been compiled using infostealer malware — malicious software that extracts sensitive information from compromised systems,” it added. “This data was stored in plain text and left completely unprotected, with no encryption or password safeguarding.” PKCERT is a federal government entity responsible for protecting Pakistan’s digital assets, sensitive information, and critical infrastructure from cyberattacks, cyberterrorism, and cyber espionage. It outlined the potential impacts of the data breach, warning that the stolen credentials could be used for account takeovers, identity theft and unauthorised access to government portals or other sensitive sites, among other potential threats. The advisory highlighted that the publicly hosted database was storing credentials stolen from “infected endpoints” without any form of authentication or protection and “included sensitive login information for major platforms, enterprises, government agencies, and financial institutions”. “Attackers may exploit this breach through credential stuffing across services with reused passwords; phishing attacks using associated emails and historical data; targeted social engineering leveraging exposed personal content; unauthorised access to business and government accounts; and malware deployment using existing email and password combinations,” the advisory warned. PKCERT advised users to change their passwords and enable multi-factor authentication on all of their online services, particularly on financial and administrative accounts. “Use unique, complex passwords for every online service, avoid storing passwords in emails or unprotected files [and] consider a password manager to securely handle account credentials,” the advisory recommended. The advisory also recommended that people change their passwords annually and use a credible online service to find out about potential breaches. “Timely action is essential to limit the impact of this massive credential breach and prevent subsequent compromise of systems and identities,” it wrote, urging people to change compromised credentials, enforce multi-factor authentication and educate users on the risks of data breaches. In March 2024, a Joint Investiga­tion Team (JIT) formed to probe a data leak from the National Database and Registration Authority (Nadra), told the Interior Ministry that the credentials of as many as 2.7 million citizens had been compromised between 2019 and 2023. Sources told _Dawn.com_ that the JIT, headed by a senior officer of the Federal Investigation Agency and comprising representatives from various intelligence agencies, had completed its probe and subsequently submitted a report to the ministry. The JIT found that Nadra offices in Karachi, Multan and Peshawar were allegedly involved in the data leak and recommended action against various officials.
www.dawn.com
May 26, 2025 at 6:57 PM
Pakistani citizens warned against phishing scams
ISLAMABAD: The National Cyber Emer­gency Response Team of Pakistan (PKCERT) has issued an advisory warning citizens against a new wave of phishing attacks, urging them to remain vigilant against online fraud. The advisory says that a new phishing and spoofing attack campaign is actively targeting Pakistani citizens through fraudulent emails impersonating law enforcement authorities. It highlights the importance of vigilance against phishing attacks impersonating law enforcement authorities, urging individuals and organisations to follow the recommended precautions and report any suspicious emails. “By staying informed and adopting proactive security measures, we can collectively mitigate the risks associated with cybercrime and phishing scams,” it says. PKCERT is a federal government entity responsible for protecting Pakistan’s digital assets, sensitive information, and critical infrastructure from cyberattacks, cyberterrorism, and cyber espionage. The advisory adds that these emails falsely claim to be from the “Office of Commissioner Police Department” and accuse recipients of cybercrime offences. The campaign aims to instil fear and manipulate victims into responding, potentially exposing their personal and financial information. The PKCERT has identified multiple red flags indicating that these emails are part of a broader social engineering attack. It also lists the details of phishing styles, highlighting that the fraudulent email campaign employs fear-based tactics to pressure recipients into responding. “The email falsely claims legal action will be taken within 24 hours unless the recipient complies, and the primary red flags include mainly from non-existent law enforcement authorities like the Commissioner Police Depa­rtment, Central Bureau of Inve­stigation, etc. that are non-existent in Pakistan,” the advisory says. It says that those involved in such fraudulent activities also use the names of laws that are either not applicable or do not exist in Pakistan. The key tool of those involved in phishing is the pressure of urgency and threats of arrest, media exposure, blacklisting, etc. “The general public must rem­ember that these criminals use fake email domains and the legitimate Pakistani government dom­ains are ‘gov.pk’,” it says. Among the key risks and threats of such attacks are identity thefts, as the victims may unknowingly provide personal details to attackers, and financial fraud, as the scammers may use fear tactics to trick victims into making payments or providing financial information. The victims face credential theft and responding to the email may expose login credentials, enabling attackers to hijack online accounts. PKCERT recommended that citizens should not respond to such emails and also verify the sender’s authenticity by checking whether the email originates from a legitimate government domain such as gov.pk. It also urged the public to monitor bank accounts and emails regularly for unauthorised activity and report phishing attempts to the PKCERT or relevant law enforcement agencies. _Published in Dawn, February 20th, 2025_
www.dawn.com
February 20, 2025 at 5:22 AM
Feed: "Pakistan Observer"
By: Staff Report on Monday, January 5, 2026
Pakistan joins hands with Kaspersky to strengthen cybersecurity
The National Computer Emergency Response Team of Pakistan (PKCERT) has joined hands with Kaspersky to enhance Pakistan’s cybersecurity.
pakobserver.net
January 5, 2026 at 11:17 AM
IRS, PKCERT join hands to promote cybersecurity research, capacity building
- Advertisement - ISLAMABAD, Jan 26 (APP):The Ins

https://en.tezkhabar.tv/irs-pkcert-join-hands-to-promote-cybersecurity-research-capacity-building/
#TezkhabarNews #Tezkhabar #News #Live #PakistanNews #Pakistan #Headline
January 26, 2026 at 11:48 AM