What happened?
Six United Bank Limited (UBL) clients reported a total loss of about Rs 10.45 million after fraudsters created duplicate SIM cards that intercepted the one‑time passwords (OTPs) sent by the bank. Using these cloned numbers, the criminals initiated unauthorized fund transfers from the victims’ accounts.

Why does it matter?
The incident exposes a critical gap where personal data from mobile operators and banking systems intersect, allowing scammers to bypass two‑factor authentication. In Pakistan, where mobile banking and OTP‑based security are widespread, such a breach jeopardises the confidence of millions of users who rely on their phones for financial transactions. It also raises concerns about the adequacy of data‑protection practices at telecom providers and banks.

What happens next?
During a hearing before the Lahore High Court, the complainants demanded a thorough investigation and stricter regulatory oversight of both telecom and banking sectors. Authorities have indicated they will trace the source of the data leak, audit SIM‑issuance procedures, and consider tighter authentication mechanisms—such as biometric verification—to curb similar fraud in the future. UBL has promised to cooperate with investigators and to review its security protocols for OTP delivery.