
A complete plain-English guide to online fraud, hacking, blackmail, harassment, Pakistani law, evidence, NCCIA complaints, court decisions, and digital safety.
Legally reviewed: 9 August 2026
Reading level: Plain English for students, parents, workers and small businesses
Important: Laws, portals and court cases can change. Check the linked official source before taking action.
Cyber crime can begin with one ordinary tap. A fake bank message arrives. A student opens a “scholarship form.” A seller trusts a false payment screenshot. A woman receives a threat that her private picture will be shared. A business employee pays an invoice sent from a look-alike email address. Within minutes, money, identity, privacy or years of family trust may be at risk.
The first response should not be panic. It should be a plan.
Need help now? If someone is in immediate physical danger, call the police emergency service or go to the nearest police station. If money has just been transferred, call the bank or wallet provider through its official number immediately and ask it to block the affected channel and flag the beneficiary transaction. Then submit a complaint to the National Cyber Crime Investigation Agency complaint portal or call the official 1799 helpline. Save evidence before deleting, blocking or resetting anything.
This guide explains what cyber crime means, the 21 threats people commonly face, the punishments under Pakistan’s current electronic-crimes law, and the exact evidence that can turn a weak story into a useful complaint. It also corrects old online guides that still send victims only to the former FIA Cyber Crime Wing.
Table of Contents
Start Here: The 60-Second Action Plan That Can Limit the Damage
Use this order when a cyber crime incident is fresh:
- Protect life first. For threats of violence, kidnapping, forced meeting, stalking near a home, or danger to a child, contact the police at once. Do not wait for an online form.
- Stop the loss. Call the bank, card issuer, mobile wallet, email provider or social platform through a number or page you find independently. Do not use a number sent by the suspected scammer.
- Preserve the trail. Save full screenshots, URLs, usernames, phone numbers, email headers, transaction IDs, dates and original files. Keep an untouched backup.
- Secure clean access. From a safe device, change the affected password, sign out unknown sessions and turn on multi-factor authentication. Do not factory-reset the affected device before important evidence is preserved.
- Report through the right route. File with NCCIA, save the complaint number and keep a dated follow-up record.
- Do not make it worse. Do not pay a blackmailer, hack back, threaten a suspect, publish a CNIC, or forward intimate or child sexual material.
A cyber crime complaint is an intake step. It does not automatically become an FIR, arrest, conviction or refund. The facts must be checked, the correct offence must be identified, and admissible evidence must support the claim.
What Is Cyber Crime? The Simple Meaning Most Guides Make Too Complicated
Cyber crime is an unlawful act in which a computer, phone, online account, network or digital data is the target, the tool, or both.
- If someone breaks into an email account, the account and data are the target.
- If someone uses WhatsApp to deceive a buyer into sending money, the phone and app are the tool.
- If malware steals bank credentials and then uses them for fraud, technology is both the target and the tool.
This broad idea is also reflected in the useful background classifications on Wikipedia’s cybercrime overview, the security explanation by Kaspersky, and Pakistan’s own Prevention of Electronic Crimes Act, 2016, commonly called PECA.
The word is often written as “cybercrime,” while many people search for “cyber crime.” The spelling does not decide whether an act is illegal. The legal ingredients do. A rude message, failed online deal or disputed debt is not automatically a criminal offence. Dishonest intention, lack of authority, false information, wrongful gain, harm, repeated contact or another required element must be proved under the relevant section.
Why Pakistan Cannot Treat This as “Only an Internet Problem”
Cyber crime harm moves from screens into real life. An account takeover can empty a salary account. A leaked CNIC can support impersonation. A deepfake can damage dignity. A child can be groomed through a game. Ransomware can stop a hospital, factory or shop. False public information can create fear. A copied customer database can destroy business trust.
Pakistan’s law therefore covers more than “hacking.” Section 1 of PECA applies throughout Pakistan, to Pakistani citizens wherever they may be, and to certain acts committed outside Pakistan when they affect a person, property, information system or data located in Pakistan. That cross-border reach matters because a scammer, server, platform and victim may all be in different places.
For a cyber crime response, it is equally important to separate three routes:
| Problem | First practical route | Why it matters |
|---|---|---|
| A PECA offence such as hacking, electronic fraud, identity misuse or cyberstalking | NCCIA complaint portal | NCCIA is the current investigation agency established under section 29 of PECA. |
| A bank, card or wallet transaction dispute | The financial institution first; then the SBP Sunwai portal where appropriate | Fast notice may help block channels, trace a transaction or preserve records. It does not guarantee recovery. |
| A fraudulent call or SMS number | The telecom operator first; then the PTA complaint portal | Blocking a number is different from criminal investigation. |
| A technical attack on an organisation or critical system | Internal incident response and National CERT incident reporting, plus NCCIA where an offence is suspected | Technical containment and criminal reporting serve different purposes. |
| Immediate violence, abduction or physical danger | Police emergency response and nearest police station | Personal safety cannot wait for portal processing. |
One cyber crime incident may require more than one route. Reporting a scam number to PTA does not replace a criminal complaint. A platform takedown does not replace evidence preservation. A bank dispute does not replace NCCIA where electronic fraud is suspected.
The 21 Cyber Crime Threats Hiding Behind Everyday Screens

The following cyber crime list connects real-life danger with the main legal and safety issue. It is not a substitute for charge-by-charge legal advice.
1. A Stolen Password Can Open Your Whole Life
Unauthorized access is a common cyber crime risk. It happens when a person enters a system or data without permission and with the required dishonest intention. A guessed password, stolen session cookie, secretly used unlocked phone or compromised email may become the entry point. Section 3 of PECA covers unauthorized access; sections 4 and 5 address unauthorized copying, transmission and interference.
Do now: revoke unknown sessions, change passwords from a clean device, turn on multi-factor authentication and save login alerts. Do not erase the affected phone before preserving useful logs.
2. A Quiet Data Copy Can Be More Dangerous Than a Loud Attack
This form of cyber crime may cause no visible damage to a device. The intruder may quietly copy customer lists, family photos, examination records, source code or private chats. A former employee may also exceed the access that was actually authorized. Permission is the key question: access to public material is different from taking restricted data.
Do now: record which files were exposed, preserve access logs, disable only the compromised credentials and avoid changing every system before a forensic copy is considered.
3. Malware and Ransomware Can Lock a Home or Business
Malware-driven cyber crime can steal, corrupt, encrypt or destroy data. Ransomware may also copy files before encryption and threaten to publish them. Section 23 of PECA covers malicious code, while other sections may apply to access, interference, fraud or extortion-related conduct.
Do now: disconnect the affected device from networks, do not plug clean backup drives into it, preserve the ransom note and consult a competent incident responder. Payment is risky and does not promise a working key or silence.
4. Phishing Wins by Creating Urgency, Not by Looking Foolish
This cyber crime method may pretend to come from a bank, courier, tax office, university, employer, friend or online marketplace. Modern phishing messages can have correct grammar, copied logos and a familiar writing style. The goal is usually to steal a password, OTP, card detail or payment.
Do now: do not open the link again. Save the full message and URL, contact the real organisation through its official website, and change exposed credentials from a safe device.
5. Online Financial Fraud Can Empty an Account in Minutes
Fake investment groups, task jobs, prize messages, advance-fee offers, false e-commerce pages, romance scams and forged payment receipts all use deception for wrongful gain. Section 14 of PECA deals with electronic fraud; the Pakistan Penal Code may also apply to cheating, forgery, criminal intimidation or abetment, depending on the facts.
Do now: call the bank or wallet provider immediately, ask for a complaint or dispute reference, save beneficiary details and report the cyber crime to NCCIA. Recovery depends on speed, traceability, available funds and evidence; no honest guide can promise it.
6. Identity Theft Can Make the Victim Look Like the Offender
Identity-based cyber crime can use CNIC images, selfies, biometric information, passwords, SIM details and account recovery codes to open or control accounts. Section 16 punishes unauthorized obtaining, sale, possession, transmission or use of identity information. Section 17 addresses unauthorized SIM issuance.
Do now: tell the relevant bank, wallet, telecom company and account provider; preserve verification messages; and request records or blocking through official channels.
7. Fake Profiles and Spoofed Websites Borrow Trust to Steal
This cyber crime technique may copy a lawyer, officer, brand, relative or public figure. A spoofed website or message uses a counterfeit source so that it appears authentic. PECA section 26 specifically covers spoofing, while sections 14, 16, 20 or 21 may apply when fraud, identity misuse, false personal harm or sexual blackmail is involved.
Do now: capture the profile URL and numeric account ID where visible. A display name alone is weak because it can be changed.
8. Repeated Messages Can Cross the Line into Cyberstalking
Cyber crime law treats context and repetition as important. Section 24 covers conduct such as repeatedly contacting a person after clear disinterest, monitoring electronic use, spying in a way that creates fear or serious distress, or distributing a person’s photo or video without consent in a harmful manner. One unpleasant message and a repeated campaign are not the same factual case.
Do now: send one clear “do not contact me” message only if safe, then preserve the repeated contacts and report threats. Do not arrange a private meeting.
9. Cyberbullying Can Follow a Child Home from School
Child-focused cyber crime may use group chats, gaming platforms, edited pictures, rumours, threats or humiliating videos. PECA section 24A defines cyberbullying and sets a specific punishment for child cyberbullying. A guardian can seek action for a minor.
Do now: protect the child from blame, save the material, inform the school when classmates are involved, tighten account privacy and report serious threats or sexual content promptly.
10. Online Harassment Is Not “Just Ignore It”
Harassment-related cyber crime can include threats, obsessive contact, monitoring, impersonation, targeted humiliation or sexual pressure. Different conduct may fall under sections 20, 21, 24 or 24A. If it is connected with employment, the Protection Against Harassment of Women at the Workplace Act, 2010 and an internal workplace process may also matter.
Readers dealing with an employment setting can also use Qanooni Dastak’s related guide on women harassment law in Pakistan.
11. Sexual Blackmail and Deepfake Intimate Images Demand Fast, Careful Action
This deeply personal form of cyber crime may fall under PECA section 21, which covers sexually explicit images or videos, face superimposition, sexual threats, inducement and conduct used to harm, take revenge or blackmail. This can include manipulated material when the statutory ingredients are present.
Do now: do not pay, bargain or send more content. Preserve the account, URL, threat and payment demand. Do not circulate the intimate file among relatives “for proof.” Provide only what an official investigator or lawyer safely requires.
12. Child Sexual Abuse Material Must Never Be Downloaded or Forwarded
Sections 22, 22A, 22B and 22C cover child sexual abuse material, grooming, commercial sexual exploitation, and digital contact linked to kidnapping, abduction or trafficking of a minor for sexual abuse or exploitation. The statute still uses an older label for section 22, but child sexual abuse material is the safer, victim-centred term.
Do now: record the URL, account name, time and platform without downloading, saving or forwarding the material. Report it immediately. Protect the child’s identity.
13. Doxxing Turns Private Details into a Weapon
Privacy-based cyber crime can include publishing a home address, private number, family details, medical information or identity record to support intimidation, stalking or fraud. Pakistan does not yet have one comprehensive general personal-data statute in force; the 2023 Personal Data Protection Bill remains a draft, according to current 2026 legal overviews. PECA sections 16, 20, 24 and 41 may still apply to particular misuse or unlawful disclosure.
Do now: preserve where the data appeared, request platform removal after evidence is saved, and strengthen security on accounts that use the exposed information for recovery.
14. Electronic Forgery Can Make a Fake File Look Legally Real
Forgery-related cyber crime can involve altered bank receipts, fake degrees, forged contracts, changed invoices, fabricated emails and edited database entries. Section 13 may apply when unauthentic data is intended to be treated as authentic for a legal or fraudulent purpose. PPC forgery provisions may also apply.
Do now: keep the suspicious file in its original format. A forwarded screenshot may lose metadata that the original email, PDF or document contains.
15. Online Defamation Is a Legal Minefield, Not a Shortcut for Silencing Criticism
Section 20 concerns intentionally and publicly transmitted information that the speaker knows is false and that intimidates or harms a natural person’s reputation or privacy. The section has faced conflicting constitutional rulings, discussed later in this guide. Civil defamation and PPC remedies can also exist. In Punjab, the Punjab Defamation Act 2024 may be relevant, but constitutional challenges and linked court proceedings mean case-specific advice is essential.
Truthful criticism, opinion, consumer warning and knowingly false factual allegations must not be carelessly mixed together. Before naming someone online, verify the material, avoid private identifiers and use the lawful complaint route.
16. False Public Information Is Not the Same as Every Honest Mistake
This newer cyber crime provision is section 26A, inserted in 2025. It addresses intentional dissemination or public transmission of information that a person knows or has reason to believe is false or fake and that is likely to create fear, panic, disorder or unrest in the general public or society. Its elements matter. A typo, private disagreement or unpopular opinion is not automatically the same offence.
Do now: check the original source, correction history, time, and context before forwarding a sensational claim.
17. Hate Speech Can Turn a Post into Real-World Violence
Hate-driven cyber crime may trigger section 11, which addresses information that advances or is likely to advance interfaith, sectarian or racial hatred. Other criminal and anti-terrorism provisions may apply when posts contain threats, incitement or prohibited activity.
Do now: do not quote-share harmful material merely to express anger. Preserve a safe record and report the original URL or account.
18. Terror Recruitment, Glorification and Cyber Terrorism Carry the Heaviest Risks
At the most serious end of cyber crime, sections 9 to 12 address glorification of terrorism-related offences or proscribed actors, cyber terrorism, hate speech, and online recruitment, funding or planning of terrorism. These are serious offences with high maximum penalties.
Do now: do not join, test, download or redistribute suspicious material. Report credible threats through the proper authorities.
19. Spam Becomes Illegal When It Is Harmful, Fraudulent, Misleading or Abusive
Spam-related cyber crime is addressed by section 25, which covers harmful, fraudulent, misleading, illegal or unsolicited information in the stated circumstances. Direct marketers must provide an unsubscribe option. A marketing message and a phishing link may look similar, but their legal and evidential facts can differ.
Do now: unsubscribe from genuine marketing, report fraudulent links, and never reply with passwords or identity details.
20. Software Piracy and Digital Copyright Theft Have Their Own Legal Route
Copyright-related cyber crime questions need careful classification. Copying software, films, photographs, books or code without permission may involve the Copyright Ordinance, 1962. It becomes a PECA issue only when PECA’s separate ingredients, such as unauthorized access or copying of restricted data, are also present. Not every copyright dispute is cyber crime.
Do now: preserve ownership records, licences, publication dates, source files and the infringing URL. Use the correct civil, criminal, platform or IP remedy.
21. One Fake Invoice Can Defeat a Strong Business
Business cyber crime includes email compromise, where a criminal impersonates a director, supplier or client and changes payment instructions. Other business attacks include database theft, insider misuse, denial-of-service and attacks on critical infrastructure.
Do now: require a second-person approval for payment changes, verify new account details through a known number, preserve full email headers, and maintain offline or immutable backups. A business should treat cyber crime as financial control, staff training, legal readiness and technical security—not merely an IT problem.
The Law Has Changed: PECA 2016 Must Be Read with the 2023 and 2025 Amendments
Pakistan’s main cyber crime statute is the Prevention of Electronic Crimes Act, 2016. Do not rely on a 2016 copy without later amendments. The official consolidated PECA text carries amendments through Act II of 2025, while the National Assembly hosts the final Prevention of Electronic Crimes (Amendment) Act, 2025.
The 2023 amendment added stronger child-protection offences, victim and witness safeguards, in-camera trial provisions, cyberbullying rules and related measures. The 2025 amendment added a social-media regulatory structure, section 26A on false and fake information, revised procedure, and placed NCCIA in section 29 as the investigation agency.
NCCIA, Not the Old FIA Cyber Wing: The Update Every Victim Must Know
Under the current section 29, the Federal Government is to establish the National Cyber Crime Investigation Agency for inquiry, investigation and prosecution of PECA offences. The law states that after NCCIA’s establishment, the former FIA Cyber Crime Wing ceases to exist and its people, cases, inquiries, assets and connected matters transfer to NCCIA.
This is why the current official routes are:
- NCCIA main website
- NCCIA online complaint form
- NCCIA office directory
- Urdu and English complaint proforma
- official 24/7 helpline: 1799
The Punjab Women Development Department complaint page supplied for this article still points readers toward an older FIA/NR3C route. It remains useful as a historical awareness page, but it does not reflect the newer statutory transfer. A person reporting cyber crime in 2026 should use the current NCCIA portal and office information.
The Social-Media Authority Route Is Different from a Criminal Complaint
The 2025 amendment also created a statutory framework for a Social Media Protection and Regulatory Authority, a Complaint Council and tribunals. Section 2C says a person aggrieved by false or fake information may seek removal or blocking and directs the Authority to act within 24 hours of receiving such an application.
That wording should not be turned into a false promise that NCCIA will investigate every cyber crime complaint within 24 hours. Content regulation, criminal investigation, bank action and platform moderation are separate functions. The practical availability of a statutory body or remedy may also depend on establishment notifications, rules and operational arrangements. Check the current official channel before filing.
PECA Punishments at a Glance: Read the Ingredients, Not Only the Number
The table below gives the statutory maximum or range shown in the consolidated federal text. “Up to” means the court may impose a lower sentence after trial; it does not mean every accused receives the maximum. A fine may be imposed with imprisonment where the provision allows both.
| PECA section | Main conduct in simple words | Statutory punishment shown in current text |
| 3 | Dishonest unauthorized access to a system or data | Up to 3 months, fine up to Rs50,000, or both |
| 4 | Dishonest unauthorized copying or transmission of data | Up to 6 months, fine up to Rs100,000, or both |
| 5 | Dishonest interference with or damage to a system or data | Up to 2 years, fine up to Rs500,000, or both |
| 6 | Unauthorized access to critical-infrastructure system or data | Up to 3 years, fine up to Rs1 million, or both |
| 7 | Unauthorized copying or transmission of critical-infrastructure data | Up to 5 years, fine up to Rs5 million, or both |
| 8 | Interference with critical-infrastructure system or data | Up to 7 years, fine up to Rs10 million, or both |
| 9 | Glorification of terrorism-related offence, convicted actor or proscribed activity | Up to 7 years, fine up to Rs10 million, or both |
| 10 | Cyber terrorism based on the specified offences and intent | Up to 14 years, fine up to Rs50 million, or both |
| 11 | Interfaith, sectarian or racial hate speech | Up to 7 years, fine, or both |
| 12 | Online terrorism recruitment, funding or planning | Up to 7 years, fine, or both |
| 13 | Electronic forgery | Up to 3 years and/or Rs250,000; critical-infrastructure form up to 7 years and/or Rs5 million |
| 14 | Electronic fraud for wrongful gain | Up to 2 years, fine up to Rs10 million, or both |
| 15 | Making, obtaining or supplying a device for a PECA offence with required intent or belief | Up to 6 months, fine up to Rs50,000, or both |
| 16 | Unauthorized obtaining, sale, possession, transmission or use of identity information | Up to 3 years, fine up to Rs5 million, or both |
| 17 | Unauthorized SIM or similar subscriber module issuance | Up to 3 years, fine up to Rs500,000, or both |
| 18 | Unauthorized tampering or reprogramming of a device identifier | Up to 3 years, fine up to Rs1 million, or both |
| 19 | Dishonest unauthorized interception by technical means | Up to 2 years, fine up to Rs500,000, or both |
| 20 | Knowingly false public information that intimidates or harms a natural person’s reputation or privacy | Up to 3 years, fine up to Rs1 million, or both; constitutional dispute explained below |
| 21 | Sexually explicit manipulation, display, threat, inducement, revenge or blackmail covered by the section | Adult victim: up to 5 years and/or Rs5 million; minor victim: up to 7 years and fine up to Rs5 million; repeat minor-victim offence: 10 years and fine |
| 22 | Child sexual abuse material covered by the provision | 14 to 20 years and fine of at least Rs1 million |
| 22A | Online grooming, solicitation or cyber enticement of a minor | 5 to 10 years and fine from Rs500,000 to Rs10 million |
| 22B | Commercial sexual exploitation of children through a system | 14 to 20 years and fine of at least Rs1 million |
| 22C | Digital contact linked to kidnapping, abduction or trafficking of a minor for sexual abuse or exploitation | 14 to 20 years and fine of at least Rs1 million |
| 23 | Malicious code intended to harm a system or data | Up to 2 years, fine up to Rs1 million, or both |
| 24 | Cyberstalking | Up to 3 years and/or Rs1 million; if the victim is a minor, up to 5 years and/or Rs10 million |
| 24A | Child cyberbullying | 1 to 5 years and fine from Rs100,000 to Rs500,000 |
| 25 | Harmful, fraudulent, misleading or illegal spam | Up to 3 months and/or fine from Rs50,000 to Rs5 million; separate escalating fines apply to unsolicited marketing violations |
| 26 | Spoofing through a counterfeit source | Up to 3 years, fine up to Rs500,000, or both |
| 26A | Intentional false or fake public information likely to cause fear, panic, disorder or unrest | Up to 3 years, fine up to Rs2 million, or both |
| 41 | Harmful unauthorized disclosure of personal material by a service provider, officer or other covered person | Up to 3 years, fine up to Rs1 million, or both |

Why the exact charge matters: PECA section 43 now makes specified offences—including sections 13, 14, 20, 22, 22A, 22B, 22C and 26A—cognizable, non-bailable and non-compoundable in the terms of its amended text, alongside the other listed serious provisions. The consolidated wording contains an awkward overlap in its two subsections. Never decide arrest or bail risk from a social post; have the FIR and exact section checked by a criminal-law practitioner.
Pakistan’s Wider Legal Net: The Other Laws a Serious Guide Must Cover
A correct cyber crime analysis never reads PECA alone. Its sections 28 and 50 expressly connect it with other laws. The right law depends on what was done, who did it, where it happened, what was intended and what evidence exists.
| Law or instrument | How it can connect with a digital incident |
| Constitution of Pakistan | Article 10A protects fair trial and due process; Article 12 bars retrospective punishment; Article 14 protects dignity and privacy; Articles 19 and 19A protect expression and access to information subject to lawful limits. These rights shape how cyber crime laws are interpreted. |
| Pakistan Penal Code, 1860 | Cheating, extortion, criminal intimidation, defamation, insult to modesty, forgery, use of forged material, abetment or conspiracy may accompany online conduct. The facts must satisfy each PPC section. |
| Code of Criminal Procedure, 1898 | Governs criminal procedure where PECA does not provide a different rule, including investigation, arrest, bail and trial procedure. |
| Qanun-e-Shahadat Order, 1984 | Article 164 permits evidence made available through modern devices, subject to relevance, authenticity and other evidential rules. A screenshot still needs context and proof of origin. |
| Electronic Transactions Ordinance, 2002 | Gives legal recognition to electronic documents and signatures and supports questions of originality and electronic records. Its former criminal sections 36 and 37 were omitted by PECA. |
| Investigation for Fair Trial Act, 2013 | Provides a warrant-based framework for specified surveillance and interception. PECA section 39 refers to a designated agency under this Act for court-ordered real-time collection. |
| Payment Systems and Electronic Fund Transfers Act, 2007 | Relevant to payment systems, electronic fund transfers, duties and disputes; it can sit beside a fraud complaint but does not make every disputed transfer a proven offence. |
| Anti-Money Laundering Act, 2010 | May matter when criminal proceeds are concealed, moved or layered through mule accounts or other arrangements. It is not automatically added to every online scam. |
| Defamation Ordinance, 2002 | Provides a civil defamation route in applicable cases, separate from criminal provisions. Province-specific law may also affect the forum and remedy. |
| Punjab Defamation Act 2024 | Covers defamation including through social media in Punjab, but its provisions are under constitutional challenge and court proceedings were still active in 2026. Obtain current advice before filing. |
| Protection Against Harassment of Women at the Workplace Act, 2010 | Online messages, images or retaliation connected with work may also trigger workplace complaint remedies. An employer process and NCCIA complaint can address different legal wrongs. |
| Punjab Protection of Women against Violence Act 2016 | In Punjab, technology-facilitated abuse may form part of a wider pattern of domestic, psychological or economic violence and protective relief may be relevant. |
| Copyright Ordinance, 1962 | Protects copyright in software and other works. Use it for IP infringement; do not force every piracy dispute into PECA. |
| Pakistan Telecommunication (Re-organization) Act, 1996 | Establishes the telecom regulatory framework and PTA functions. PTA can address fraudulent numbers and telecom issues; NCCIA investigates PECA offences. |
| National Forensics Agency Act, 2024 | Supports the national forensic framework, important where devices, documents, voice, images or other technical evidence require expert examination. |
| National Cyber Security Policy 2021 and CERT Rules 2023 | These support national resilience and incident response. They are policy and operational instruments, not a substitute for a victim’s criminal complaint. |
| Personal Data Protection Bill 2023 | As of the legal review date, Pakistan had not enacted a comprehensive, general personal-data protection Act. The Bill remains a draft. Never describe it as an active “Data Protection Act.” |
This wider map prevents two common errors. First, cyber crime does not replace ordinary criminal, civil, banking, workplace or intellectual-property law. Second, a civil wrong or policy breach does not become a crime simply because a phone was used.
Your Phone Is Evidence: The 12 Items That Can Make a Complaint Stronger

A useful cyber crime complaint tells a clear story and preserves the original digital trail. Build one folder with a short timeline and separate subfolders for messages, money, accounts and official follow-up.
- A one-page timeline: date, time, event, platform, amount and what you did next.
- Full screenshots: include the account name, number, date, time and surrounding conversation. Avoid tight crops.
- Exact URLs and account IDs: save the profile, post, group, channel or website link. Usernames can change.
- Original chats: export them where the app permits. Keep the original device and backup.
- Original email: save the
.emlfile or full headers, not only a picture of the email body. - Call evidence: numbers, call logs, dates, duration, voicemails, and lawful recordings already in your possession.
- Financial trail: transaction ID, account title, IBAN, wallet number, amount, time, receipt and bank statement entry.
- Fake documents or ads: preserve the original PDF, image, invoice, job post, marketplace listing or payment screenshot.
- Security alerts: login location, device name, password-reset message, recovery-email change or session history.
- Witness details: name and contact of anyone who saw the message, transfer, call or meeting.
- Your official references: bank ticket, platform report, PTA complaint, NCCIA number and follow-up date.
- An untouched backup: keep original files read-only where possible. Record when and how each file was copied.
PECA itself requires officers to protect integrity, secrecy and chain of custody during search and seizure. It also states that an authorized officer should act proportionately and avoid disrupting unrelated data or legitimate business. These principles explain why edited screenshots and repeatedly forwarded files can create avoidable questions.
Evidence Mistakes That Can Damage a Real Cyber Crime Case
- deleting the full chat after saving only one dramatic message;
- editing, annotating or compressing the only copy;
- resetting the phone before account and device records are saved;
- asking friends to message or trap the suspect;
- sending money “one last time” to collect proof;
- publishing the suspect’s family details or CNIC;
- forwarding an intimate image to multiple people;
- downloading child sexual abuse material;
- presenting assumptions as confirmed identity;
- submitting a long emotional story without dates, links or transaction numbers.
Evidence preservation is not permission to keep illegal material unnecessarily. For intimate or child-related content, record the minimum safe identifiers and obtain official guidance promptly.
How to File a Cyber Crime Complaint with NCCIA Without Missing the Key Facts

Step 1: Confirm That You Are Using an Official Address
Open the NCCIA complaint portal by typing or bookmarking the address. The official site lists helpline 1799. Do not trust a paid “agent,” random WhatsApp number or sponsored search result that asks for your password, OTP or remote access.
If online submission is not possible, use the official NCCIA office directory or download its complaint proforma. Check the current office details before travelling.
Step 2: Write the Story in Date Order
Begin with one sentence:
“I request inquiry and lawful action regarding suspected [electronic fraud / account access / harassment / blackmail / identity misuse] that occurred through [platform] between [dates].”
Then state:
- your name, CNIC and safe contact information;
- what happened, in short numbered paragraphs;
- the exact date and time of each major event;
- the platform, number, email, URL and account ID;
- the amount and transaction details, if money was involved;
- the threat, false representation or unauthorized act;
- what access, consent or authority did or did not exist;
- what evidence is attached;
- which bank, platform, telecom operator or police station has already been contacted; and
- the relief requested, such as preservation, inquiry, tracing and action according to law.
Do not guess an offender’s identity. Write “the account using this name” unless identity is supported. Do not demand a particular section as if it has already been proved. You may mention suspected provisions, but the facts and evidence should lead the classification.
Step 3: Upload Evidence in an Order an Investigator Can Follow
Use clear filenames, for example:
01-timeline.pdf02-profile-url-and-id.pdf03-full-chat-export.zip04-transaction-receipt-original.pdf05-bank-complaint-reference.pdf06-email-with-full-headers.eml
Keep a separate untouched copy. If the portal has size or file-type limits, submit the essential material and state that originals are available. Never upload unrelated intimate data, family documents or an entire phone backup without a lawful reason.
Step 4: Save the Number and Follow Up Calmly
Save the confirmation screen, complaint number, submission date and attached-file list. Record every later call, email, visit and officer name. A cyber crime inquiry can require platform data, subscriber records, bank information, forensic work or a court order. The time will differ by case.
Do not repeatedly file new complaints for the same event unless an official asks you to do so. Add new evidence by referring to the original number.
Money Was Sent: The First Hour Is More Important Than a Long Facebook Post
If a scam payment has just occurred, use this sequence:
- Call the bank, card issuer or wallet through its official app, card or website.
- Ask it to block compromised cards or digital channels immediately.
- Ask it to flag the beneficiary account or wallet and attempt lawful hold, recall or dispute action.
- Obtain a written complaint or ticket number.
- Save the transaction ID, beneficiary name, IBAN or wallet number and statement entry.
- File the cyber crime facts with NCCIA.
- If the institution does not resolve the banking complaint, use the State Bank consumer-protection route and Sunwai as appropriate.
- Report the scam number to the telecom operator and, where needed, the PTA complaint system.
State Bank guidance treats the bank or regulated institution as the first forum for a banking complaint. The Sunwai portal can then route grievances to the proper banking redress forum. It is separate from criminal investigation.
Never tell a victim that recovery is guaranteed. A bank may block a channel quickly, yet the money may already have moved through mule accounts. A complaint can support tracing and legal action, but the result depends on the facts.
Blackmail or Intimate Images: Protect Dignity Without Destroying Evidence

Sexual blackmail creates shame on purpose. The offender wants the victim to act alone, pay quickly and keep silent. The safer response is controlled support:
- tell one trusted person;
- save the threatening account, URL, message and payment demand;
- do not send new pictures or perform a demanded act;
- stop live location sharing;
- review account-recovery details and active sessions;
- make the NCCIA complaint promptly;
- use the platform’s non-consensual intimate-image reporting route after preservation; and
- involve police immediately if there is physical danger.
For a minor, a guardian can complain. Do not interview the child again and again or force the child to repeat details to relatives. Preserve safety, privacy and access to professional support. PECA provides for victim and witness protection measures and in-camera trials for offences against minors.
What Happens After a Cyber Crime Complaint? The Process Nobody Explains
The exact path differs, but the law provides this general structure:
- Complaint and inquiry: NCCIA receives written information and checks whether PECA ingredients may be present.
- Preservation: Under section 31, an authorized officer can require specified vulnerable data to be preserved for up to 90 days and must bring the acquisition to the court’s notice within 24 hours. A court can extend preservation.
- Traffic data: Section 32 requires covered service providers to retain specified traffic data for at least one year and provide it subject to a court warrant.
- Search or seizure: Section 33 generally requires a court warrant based on reasonable grounds tied to a specifically identified offence. A narrow urgent exception appears for section 10, with later court notice.
- Content disclosure: Section 34 allows a court, after recording reasons, to order access to stored content data required for an investigation or proceeding.
- Forensic handling: Sections 35 and 36 require relevance, proportionality, integrity, chain of custody, a seizure list and safeguards for unrelated data and business operations.
- Arrest and remand: If a person is arrested, amended section 30A requires production before the court within 24 hours, excluding necessary travel. Custody cannot exceed 14 days at one time, and total such remand cannot exceed 30 days.
- Trial and compensation: Designated courts try offences. Section 45 allows compensation for victim loss in addition to punishment, without removing a right to pursue further civil damages where available.
- Appeal: Section 47 provides a 30-day appeal from a Sessions Court decision to the High Court, or from a magistrate to the Sessions Court, after the certified copy is provided.
An accused person also has constitutional rights to due process, fair trial and protection from retrospective punishment. Reporting cyber crime is necessary, but guilt is decided by a court after lawful proof and defence—not by a viral post.
Five Pakistani Court Decisions That Changed the Conversation
The table covers leading, publicly accessible Supreme Court and High Court decisions. It is not a list of every bail order, FIR petition or trial judgment ever issued under PECA.
Together, these cyber crime judgments show why dates, ingredients, procedure and constitutional rights all matter.
| Case | Court, citation and date | What the court did | Practical lesson |
| Mst. Uzma Mukhtar v. State through DAG | Supreme Court, 2024 SCMR 1520 / 2024 SCP 214, Criminal Petition 128/2024, reasons dated 11 June 2024 | The complainant alleged pre-PECA WhatsApp blackmail involving private pictures. The Court refused to add PECA sections retrospectively and found the former ETO sections 36 and 37 did not fit the proved technical acts. | Article 12 bars retrospective punishment. A terrible allegation does not permit the wrong section or a law that was not in force at the time. |
| Javed Iqbal v. State through DAG | Supreme Court, 2023 SCMR 401 / 2022 SCP 312, Crl.P.1251/2022, 1 November 2022 | The Court removed a High Court condition requiring a Rs3.5 million deposit while maintaining bail on lawful bonds and surety. | Once bail is made out, a court cannot make it illusory through an unauthorized repayment or deposit condition. Bail is not a final finding of innocence. |
| PFUJ v. President of Pakistan | Islamabad High Court, W.P.666/2022, 8 April 2022 | The Court struck down the 2022 Amendment Ordinance and declared the “harms the reputation” part of section 20 and its punishment unconstitutional in the short order; connected proceedings were quashed. | Freedom of expression and lawful limits must be balanced. This ruling does not mean every privacy threat, stalking act or false allegation became lawful. |
| Meera Shafi and others v. Federation | Lahore High Court, PLD 2022 Lahore 773 / 2022 LHC 1786, W.P.24397/2021, decided 24 December 2021 | The LHC rejected the constitutional challenge to section 20 and held that protection of dignity could coexist with free-expression rights and other defamation remedies. | This conflicts with the later IHC short order. The Supreme Court granted leave in the Meera Shafi matter in 2022 and stayed the criminal proceedings pending consideration. |
| Usman Zulfiqar Khan v. State | Lahore High Court, 2022 LHC 6401, W.P.19711/2022, 27 June 2022 | The Court quashed a PECA/PPC FIR arising from a consumer’s Facebook video about a superstore product, finding the charge groundless on the record and the FIR procedurally unlawful under the then-applicable classification. | A factual consumer warning or criticism is not automatically cyber crime. But the 2025 amendment changed the cognizable and bail treatment of several provisions, so old procedure cannot be copied blindly. |
The Section 20 Conflict: What a Careful Reader Should Understand in 2026
The LHC upheld section 20. The IHC later struck part of it in a short order. The Supreme Court granted leave to examine important constitutional questions in the Meera Shafi case and stayed the criminal proceedings there. The 2025 Act then amended PECA more broadly, and fresh constitutional challenges were filed.
The responsible conclusion is not “section 20 is fully dead” or “every online criticism is a crime.” The legal position has conflict, later legislation and case-specific orders. The official consolidated PECA still prints section 20. Before filing or defending a reputation-based cyber crime case, check the latest final constitutional judgment, the territorial forum, the date of the alleged act, the exact wording in force, and whether the statement is a fact, opinion, private communication or public transmission.
What Major International Sources Add—and What Pakistan-Focused Guides Often Miss
Kaspersky’s global explainer treats computers as both targets and tools. Its prevention advice is practical: install security updates, use strong passwords, avoid unknown attachments and links, protect personal information and call an organisation through an independently verified number. Norwich University’s overview groups major threats around hacking, malware, identity theft, social engineering and software piracy, then connects prevention with patching, restricted administrator access, secure email controls, backups and staff training. CyberTalents adds useful examples across harm to individuals, organisations, property and government. Together, these sources show that awareness alone is not enough; safe systems, trained people and a tested response plan must work together.
The FBI’s cyber programme stresses rapid reporting, information sharing and partnerships because technical indicators and stolen money can move quickly. Pakistan cannot copy a US reporting address, but it can copy the principle: report through the correct national channel before logs disappear and funds move again. At the international level, the United Nations Convention against Cybercrime was adopted in 2024 and opened for signature in Hanoi in October 2025. The UNODC framework focuses on cross-border cooperation and electronic evidence. It does not replace PECA, Pakistani constitutional safeguards or the need for a local NCCIA complaint.
Stop the Next Attack: A Cyber Crime Prevention Plan for Every Phone
Prevention is not one antivirus app. It is a set of small barriers. If one barrier fails, the next one should still protect the account, money or evidence.
1. Give Every Important Account a Different Password
Use a reputable password manager to create long, unique passwords. If one shopping website leaks a password, criminals should not be able to reuse it on your email or bank. Password reuse turns one cyber crime incident into several account takeovers.
2. Turn On Strong Multi-Factor Authentication
Use an authenticator app, passkey or security key where available. SMS codes are better than a password alone, but a stolen SIM or convincing caller can still create risk. Never read an OTP to a person who called you.
3. Protect the Email Account That Resets Everything Else
Your primary email can reset social, shopping and financial accounts. Review its recovery number, backup email, forwarding rules and logged-in devices. A hidden forwarding rule can keep sending messages to an attacker after a password is changed.
4. Install Updates Before an Emergency Forces You To
Update the operating system, browser, router, office software, plugins and security tools. Unsupported software may have known weaknesses that no longer receive fixes. Timely patching blocks many automated cyber crime attempts.
5. Verify Through a Second Channel
If a relative asks for emergency money, call a known number. If a supplier changes an IBAN, confirm it with a saved contact. If a bank calls, hang up and use the number on the card or official website. A family “safe word” can help expose an AI voice imitation.
6. Reduce the Amount a Criminal Can Take
Turn on transaction alerts, use suitable transfer limits, lock unused cards and keep a separate low-balance account for risky online purchases where practical. Financial controls reduce cyber crime damage even when a message looks convincing.
7. Back Up What You Cannot Replace
Keep at least one backup that is not always connected to the main device or network. Test whether files can actually be restored. A backup that has never been tested is only a hope.
8. Treat QR Codes and Short Links Like Unknown Doors
A QR code can hide a fake login or payment page. Preview the destination and check the domain carefully. Type the official address yourself for banking, government and account recovery.
9. Limit Public Clues
Birth dates, school names, family connections, travel plans and public phone numbers can help an impersonator answer security questions or design a personal scam. Review profile visibility and remove information that has no public purpose.
10. Separate Work from Personal Risk
Do not install cracked software, random browser extensions or personal game tools on a work device. Use separate accounts and minimum access. One employee should not have unlimited access to money, customer data and backups.
Parents and Schools: The Conversation That Can Prevent Silent Harm
Children need a safe adult more than a long lecture. Tell them:
- they will not lose the phone merely for reporting a problem;
- an online friend may not be the age shown on the profile;
- private pictures should never be exchanged under pressure;
- gifts, game credits and modelling offers can be grooming tools;
- location, school uniform and daily route can reveal physical access;
- blocking comes after essential evidence is saved; and
- a threat to “tell everyone” becomes weaker when a trusted adult knows.
A school cyber crime policy should explain reporting, evidence preservation, confidentiality, anti-retaliation and when parents or authorities must be involved. Publicly shaming a child can multiply the original harm.
Small Businesses: Eight Controls Cheaper Than One Serious Breach

- Require two approvals for new beneficiaries and changed payment details.
- Confirm high-value instructions through a known number, not the email being answered.
- Give staff only the access needed for their role and remove access on the last working day.
- Patch internet-facing systems and remove unused remote-access tools.
- Keep protected backups and test restoration.
- Train staff with short examples of invoices, OTP calls, fake login pages and QR traps.
- Write a one-page cyber crime response sheet with bank, technical, legal and NCCIA contacts.
- Preserve logs for a sensible period and test the plan before an incident.
National CERT publishes official advisories and can receive reports of technical incidents. A business should use that technical support route while also reporting suspected cyber crime to NCCIA and informing affected banks, customers or regulators where law and contracts require it.
The Five-Minute “Before You Click” Test
Ask five questions:
- Who benefits if I act immediately? Urgency often protects the scammer, not you.
- Can I verify this outside the message? Open the official app or call a saved number.
- Is the exact domain correct? A lock icon does not prove the business behind a website is genuine.
- Why does this person need a password, OTP, screen share or advance fee? Legitimate support should not need secret authentication codes.
- What would I advise a friend to do? Distance can expose pressure that feels normal in the moment.
This short pause prevents more cyber crime than fear-based slogans.
Frequently Asked Questions About Cyber Crime in Pakistan
What is cyber crime in one simple sentence?
Cyber crime is an unlawful act in which a phone, computer, account, network or digital data is the target, the tool, or both.
Where should I report cyber crime in Pakistan in 2026?
Use the official NCCIA complaint portal, call 1799 for guidance, or visit an office listed on the NCCIA directory. For immediate physical danger, contact police first. For a fresh money loss, contact the bank or wallet first and then NCCIA.
Is FIA still the main cyber crime complaint agency?
No. Current PECA section 29 establishes NCCIA and transfers the former FIA Cyber Crime Wing’s cases, people and connected matters after NCCIA’s establishment. Old articles and the Punjab WDD page may still show the former route.
What is the official cyber crime helpline number in Pakistan?
The official NCCIA website and complaint portal list the 24/7 helpline as 1799. Recheck the official site before publishing or calling because government contact details can change.
Is there an official NCCIA WhatsApp number for a cyber crime complaint?
The verified routes used in this guide are the NCCIA website, complaint portal, helpline and listed offices. Do not send CNIC copies, passwords or evidence to a random number claiming to be an official cyber crime desk.
Can I make an anonymous cyber crime complaint?
The formal portal asks for complainant identification and contact information. Do not assume an anonymous message will start a full inquiry. If disclosure creates a safety risk, ask NCCIA or a qualified lawyer about lawful victim-protection options.
What evidence is best for a cyber crime complaint?
The strongest package usually contains a dated timeline, full screenshots, original chat or email, exact URLs and account IDs, transaction records, login alerts, device information, witnesses and earlier complaint numbers. Relevance and authenticity matter more than hundreds of random images.
Is a screenshot legal evidence in Pakistan?
A screenshot can be relevant electronic evidence, but it is not automatically conclusive. The court may consider who made it, whether it is complete, its source, context, device, metadata, consistency and whether the other side disputes it. Article 164 of the Qanun-e-Shahadat allows evidence made available through modern devices, subject to evidential rules.
Can deleted messages or a deleted account still be traced?
Sometimes records remain on a device, backup, recipient account, service-provider system or platform. Availability depends on retention, encryption, jurisdiction, time and lawful process. Report cyber crime quickly so preservation can be considered before data disappears.
Can I recover money sent to an online scammer?
Recovery is possible in some cases but never guaranteed. Contact the financial institution immediately, request blocking or dispute action, keep the reference, and file with NCCIA. Delay makes movement through mule accounts more likely.
What is the punishment for online fraud?
PECA section 14 provides up to two years’ imprisonment, a fine up to Rs10 million, or both for electronic fraud meeting its elements. PPC cheating, forgery or other sections may also apply. The final charge and sentence depend on evidence and trial.
What is the punishment for cyber blackmail with private pictures?
Where section 21 applies, the adult-victim offence may carry up to five years and a fine up to Rs5 million; a minor-victim offence can carry higher punishment, with a special repeat-offence rule. Other PECA and PPC provisions may also apply. Do not forward the picture while reporting.
Is every false social-media post a cyber crime under section 26A?
No. Section 26A requires intentional public dissemination or transmission of information the person knows or has reason to believe is false or fake, plus likelihood of fear, panic, disorder or unrest in the general public or society. Each element requires proof.
Is online criticism or a bad review cyber crime?
Not automatically. Truth, opinion, public interest, wording, evidence, privacy, intention and the applicable defamation law matter. The Usman Zulfiqar Khan judgment shows that a fact-based consumer warning cannot be treated as an offence without legal and evidential grounds. Knowingly false factual accusations can create serious risk.
Can a child or parent file a cyber crime complaint?
Yes. PECA allows a guardian to act for a minor in several victim-related provisions. Child sexual abuse material, grooming, exploitation and serious bullying should be reported promptly without downloading or circulating the content.
Can NCCIA take my phone during a cyber crime investigation?
PECA provides warrant-based search and seizure powers and requires proportionality, relevance, integrity and a seizure list. Section 35 describes seizure of a whole device as a last resort where technical measures are insufficient. Rights and exceptions depend on the facts and order; obtain legal advice if a device is sought.
How long does a cyber crime complaint take?
There is no honest universal deadline. A simple impersonation report and a cross-border fraud with bank, telecom and platform records require different work. Save the complaint number and follow up with new evidence in an orderly way.
Can an overseas Pakistani file a cyber crime complaint?
PECA has extraterritorial reach in the circumstances stated in section 1, and the NCCIA portal is online. Explain the Pakistan connection, location of affected person or data, suspect details, transactions and a safe contact. Jurisdiction still depends on the facts.
Should I post the suspected scammer’s CNIC and number online?
No. Public accusation can expose an innocent person, compromise an investigation, spread private data and create a separate legal dispute. Give identifiers to the bank, platform, telecom operator, NCCIA or lawyer through a lawful channel.
Does reporting a cyber crime guarantee an FIR or arrest?
No. A complaint begins scrutiny. The agency must determine jurisdiction, ingredients and evidence. Arrest and remand require legal grounds, and guilt requires a court process.
What should I do if my account was hacked but no money was stolen?
Change the password from a clean device, revoke sessions, review recovery methods and forwarding rules, turn on multi-factor authentication, save login alerts and warn contacts about messages sent from the account. Report the cyber crime if unauthorized access, data theft, impersonation or another offence is suspected.
The Final Lesson: Silence Protects the Offender, but Panic Can Destroy the Proof
Cyber crime is not a sign that the victim is foolish. Criminals exploit trust, fear, affection, authority, financial need and technical weakness. The best response combines dignity with discipline: become safe, stop financial loss, preserve originals, report through NCCIA, use the separate bank or PTA route where needed, and avoid public retaliation.
Pakistan now has a broad electronic-crimes framework, stronger child-protection provisions, an independent investigation agency in the statute, forensic powers, court oversight, compensation and appeal routes. It also has difficult constitutional questions about speech, privacy and regulation. Both sides matter. The law must protect victims without treating every disagreement as cyber crime.
Save the official links. Teach the five-minute verification test. Give children a safe way to speak. Train employees before the fake invoice arrives. Most importantly, act early. One careful hour can preserve the evidence that months of anger cannot recreate.
Important Legal and Safety Disclaimer
This article provides general legal awareness, not legal advice, representation, a finding of guilt or a promise of recovery. Cyber crime law changes, and every case depends on dates, jurisdiction, evidence and the wording in force. For an active investigation, arrest risk, intimate-content case, child-safety matter or major financial loss, contact the relevant authority and a qualified Pakistani lawyer promptly.
Editorial and Source Note
This is original, independently written content. The supplied sources were read and paraphrased; no external article was copied. Official Pakistani statutes, portals and judgments were preferred for legal claims. International educational sources were used for threat classification and prevention. The article should be legally rechecked before each annual update.