Pakistan’s National Cyber Emergency Response Team (PKCERT) issued an urgent advisory on Monday, revealing that login credentials and passwords for over 180 million internet users in Pakistan have been compromised in a massive global data breach, urging immediate protective measures.
The breach, according to the PKCERT advisory seen by Dawn.com, involves a publicly accessible, unencrypted file containing over 184 million unique account credentials. The exposed data includes usernames, passwords, emails, and associated URLs for services from tech giants like Google, Microsoft, Apple, and Facebook, as well as government portals, banking institutions, and healthcare platforms worldwide.
PKCERT stated the leaked database was likely compiled using “infostealer malware”—software designed to extract sensitive information from compromised systems—and was left completely unprotected in plain text. The federal entity warned of severe potential impacts, including account takeovers, identity theft, and unauthorized access to sensitive government or financial sites. Attackers might exploit the breach via credential stuffing, phishing attacks using associated emails, or targeted social engineering leveraging exposed personal content.
To mitigate these threats, PKCERT strongly advised all users to immediately change their passwords and enable multi-factor authentication (MFA) across all online services, particularly for financial and administrative accounts. Further recommendations include using unique, complex passwords for every service, utilizing a password manager, and avoiding storing passwords in insecure formats like emails or unprotected files. The advisory also suggested annual password changes and using credible online services to check for potential breaches, emphasizing that “timely action is essential to limit the impact.”
This alert follows a March 2024 report where a Joint Investigation Team informed the Interior Ministry that credentials of 2.7 million citizens had been compromised in a data leak from the National Database and Registration Authority (NADRA) between 2019 and 2023, with alleged involvement of NADRA offices in Karachi, Multan, and Peshawar.
Total views: 750