LHC rules misuse of bank customer data may constitute a crime

LHC rules misuse of bank customer data may constitute a crime

The Lahore High Court (LHC) has ruled that customer information held by banks can be treated as property under cybercrime law and that its unauthorised use in a fraudulent scheme may constitute a criminal offence.

Justice Tariq Saleem Sheikh issued the ruling while granting post-arrest bail to a telecom franchise operator in a multi-million-rupee SIM-swap fraud case, while rejecting the bail petition of a private bank employee.

The National Cyber Crime Investigation Agency (NCCIA) had registered a case over the alleged fraudulent issuance of duplicate SIM cards using victims’ CNIC details and fingerprints, followed by unauthorised transfers totalling Rs10.45 million from the accounts of six customers.

Justice Sheikh observed that information held by banks, including account details and registered mobile numbers, falls within the definition of “data” under the Prevention of Electronic Crimes Act (Peca). He noted that Section 27(2) of the law treats such data as “property” for offences covered by the Pakistan Penal Code (PPC).

The judge said that when customer data is entrusted to a bank employee or placed under their control, its dishonest disclosure or unauthorised use to facilitate fraud could amount to criminal breach of trust. Such conduct, he added, could also violate the confidentiality obligations attached to banking employment under Section 33A of the Banking Companies Ordinance, 1962.

Justice Sheikh said electronic systems are central to modern banking, meaning control over critical customer data can effectively provide access to customers’ funds.

However, he clarified that Section 409 of the PPC, which deals with criminal breach of trust by a public servant, banker, merchant or agent, does not automatically apply to every bank employee. Instead, the employee’s actual functions and level of control over customer funds or data must be considered.

According to the ruling, Section 409 would apply where an employee is entrusted with, or exercises control over, customer funds or data used for access, verification, authentication or banking transactions as part of their duties. Employees with only incidental access would not fall under the provision.

Regarding bank employee Muhammad Atif, the judge said investigation records, internal fraud reports and account-access logs provided sufficient incriminating material. The investigation alleged that Atif had disclosed customers’ registered mobile numbers, facilitating the SIM-swap fraud.

The court therefore held that Section 409 PPC was prima facie attracted and dismissed Atif’s bail petition.

In the case of telecom franchise operator Muhammad Usman, however, the court found insufficient evidence linking him to the disputed SIM activations, alleged manipulation of the biometric verification system or the unauthorised use of customer data.

Justice Sheikh said the allegations against Usman required “further inquiry” and granted him post-arrest bail against surety bonds of Rs1 million.

Leave a Reply

Your email address will not be published. Required fields are marked *