Phishing domains impersonate govt agencies
ISLAMABAD: The National Cyber Security Emergency Response Team (NCERT) has detected a number of suspected phishing domains created in the name of key national institutions, apparently aimed at stealing sensitive information from citizens. According to the NCERT’s Threat Intelligence Centre, suspicious domains impersonating several government and public sector organisations were found active on…
ISLAMABAD - The National Cyber Security Emergency Response Team (NCERT) has uncovered numerous suspected phishing domains masquerading as official government entities, with the aim of pilfering confidential citizen data. As per the NCERT’s Threat Intelligence Centre, malicious domains resembling numerous governmental and public sector organizations were active as of October 4th.
Notable among these were domains pretending to be the National Database and Registration Authority (Nadra), Federal Board of Revenue (FBR), Higher Education Commission (HEC), Pakistan Telecommunication Authority (PTA), Federal Investigation Agency (FIA), Securities and Exchange Commission of Pakistan (SECP), Benazir Income Support Programme (BISP), and Prime Minister’s Youth Programme.
Additionally, a suspicious login domain using the name of Punjab Safe Cities was also detected. The NCERT warns citizens against disclosing personal details on unapproved websites. The Threat Intelligence Centre maintains that these suspected phishing domains remain active and are under surveillance. It cautions that phishing websites and impersonation-based attacks could trick users into divulging sensitive data like login credentials and personal information.
The NCERT urges individuals and government bodies to proceed with caution when interacting with unverified links, websites, and login pages. It urges users to confirm website authenticity before sharing any personal information, and emphasizes ongoing monitoring of phishing activities targeting national institutions. In the realm of Generative Artificial Intelligence (GenAI), the NCERT has released an advisory cautioning organizations about potential cybersecurity and data governance risks associated with the widespread use of GenAI tools and platforms.
The agency stresses that unchecked or unauthorized GenAI use, often referred to as Shadow AI, could expose sensitive information, intellectual property, credentials, source code, and organizational data to threats like prompt injection, insecure AI-generated code, malicious integrations, inaccurate outputs, and compromised third-party models.
The NCERT advises organizations to safeguard sensitive and classified information, strictly prohibiting submission of such data to unapproved AI platforms. They are directed to establish an approved AI tool registry, maintain a vetted and regularly updated inventory of authorized AI tools, models, browser extensions, plug-ins, APIs, and platforms.
Moreover, organizations must remain vigilant for sensitive data leaks, unauthorized AI plug-ins, suspicious AI access, and policy breaches. Upon detecting an AI-related incident, the NCERT recommends immediate containment of unauthorized access, preservation of evidence and logs, revocation of compromised credentials or API keys, investigation of exposure, implementation of corrective measures, and reporting the incident to the NCERT.
Written by urgent.news from Dawn's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.