UBL data leak and SIM-swap reports: what worried customers should know
If you are a customer of UBL, here’s what is being claimed, and what it would mean for you.
United Bank Limited has not confirmed this case or issued a customer notice about it. Several Pakistani outlets, citing a Lahore High Court order and investigators, report that confidential UBL customer information — including registered mobile numbers — was obtained through insider access and used in a duplicate-SIM scheme. About Rs 10.46 million was allegedly taken from six accounts; the criminal case is still underway.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
UBL customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Here for work? Check a company domain’s exposure.
United Bank Limited has not confirmed this incident. No public statement, support notice or filing from the bank about this specific case was found. What follows is what The Express Tribune, The Nation, Daily Pakistan and TechJuice independently reported from a Lahore High Court written order, a complaint to Pakistan’s telecom regulator, cybercrime investigators, and UBL internal inquiry reports that were given to those investigators — not published for customers.
According to that coverage, complaints in November 2025 said duplicate copies of customers’ mobile numbers had been issued against their national identity cards and then used to move money out of UBL accounts. Two of those replacement SIMs were reportedly issued on 6 November and 9 November 2025; the original SIMs were blocked, new devices were registered on the accounts, and funds were transferred. Investigators reportedly identified six UBL account holders in all. The amount alleged to have been taken is Rs 10,458,500 (about Rs 10.45 million). Some headlines said “Rs 10 crore”; that does not match the court and investigation record those outlets cite. A raid in November 2025 reportedly recovered SIM-related equipment and led to an arrest. A case was registered on 18 November 2025. UBL’s fraud team, as those reports recite from the court file, wrote internal notes dated 30 December 2025 on the six accounts and 29 May 2026 on a larger set of complaints, describing leakage of customers’ confidential information through insider access, including by UBL employees. In August 2026 the high court, according to the same outlets, refused bail for one employee and granted bail to another person subject to further inquiry. Authorities also reportedly said about Rs 10.5 million was recovered in June 2026 and returned to complainants. No trial verdict or conviction has been reported.
This is being told as a story about six people and a court phrase. For you, it is a phone-number story.
The coverage leads with a contained crime: six customers, a rupee total, a raid, and a legal line that customer data can count as “property.” Those points, as reported, appear to be what the court was asked to decide. They are not the part that changes what a UBL customer should do tomorrow morning.
The method described in that same court record, as the outlets retell it, starts one step earlier. Confidential banking information — including the mobile number registered on an account — was reportedly obtained through insider access, not by guessing or by breaking into a public website. That number is the switch. A second SIM in your name means the texts and approval codes meant for you go to someone else. After that, the transfer looks to the bank like you. The six losses are the cases that produced a police file and a bail hearing. They are not, on the reporting we have, a public list of everyone whose record was looked up. The bank’s second internal report, dated 29 May 2026 and recited in court according to those outlets, was described as covering a larger set of complaints. How large, and whether that means more records were accessed or only that more people later complained, has not been published.
Advertisement
Know the day any company files a breach.
Every SEC 8-K Item 1.05 and state breach notification — dated, sourced, and delivered by email + a JSON API the day it posts. Track any company, not just the ones in the news.
GalaxyWarden Signals and RecentBreaches share common ownership.
That is the honest read, not a claim that every UBL customer is in this file. We do not know who was queried. UBL has not said. The bank’s general posts about SIM scams are not a notice about this case. What an ordinary reader should take from the reporting is narrower and more useful than the headlines: the dangerous object here is the pairing of a real account with the phone number the bank will trust, and that pairing, according to the outlets citing UBL’s own internal reports, was available to people inside the bank.
What to actually expect
- Do not expect a letter, SMS or app alert from UBL that names this incident. On the available reporting, the bank has not issued a customer-facing notice about it.
- You will not get a public page where you can type your name or account number and see whether you were in the internal reports. Those reports, as described, went to investigators. A “breach check” elsewhere will not settle this.
- The near-term signal that matches this case is on your phone and on the account: a replacement SIM you did not ask for, a sudden loss of service, a new device you did not add, or a transfer you did not make. In the reported cases, the money moved after the new SIM and device were already in place.
- Bail rulings are not a verdict. The outlets describe an investigation and court argument that is still open. Treat “an employee was refused bail” as a legal update, not as proof the bank has finished with the underlying access problem.
What you can and cannot fix
What cannot be undone is the look-up itself. If an employee already opened your account record or copied the mobile number registered on it, that viewing cannot be recalled, and no company can scrub it from the people who saw it. Your national identity number cannot be changed. Nobody can honestly promise to pull this data back, and nobody can honestly tell you, from a public scan, whether your row was one of the ones opened.
What still helps, in order:
- Confirm you still control the SIM on your UBL account. That is the switch this reported scheme used. If you did not request a new SIM, and you lose service or get a registration message you did not cause, contact your mobile operator and the bank the same day and say you are worried about a duplicate SIM on the number tied to the account.
- Read the account itself for the next traces this case actually left: transfers you did not make, and devices or numbers added that you do not recognise. That is how the reported thefts showed up once the new SIM was live.
- Ask your operator, before you need it, what extra checks they will apply before anyone can take out a replacement SIM against your national identity card. The complaints described in court, as reported, began with those replacement SIMs being issued.
- Shrink the extra personal detail about you that sits in people-search and directory listings. A bank-side note that only ties a name to a registered mobile number becomes much easier to use when it can be joined to listings that add relatives, other phone numbers, employers and old addresses. Those listings, unlike whatever was already viewed inside the bank, can actually be taken down. The leaked or accessed bank record cannot.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on UBL.
- Tell your bank before you do anything else. Account and routing details are the fastest-moving of the fields in this notice. Call the number on the back of your card rather than any number in an email, and ask them to watch the account and reissue the card.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.
For security and vendor-risk teams: get an alert the day a vendor you watch files a breach with a US regulator or the SEC — the filing itself, dated and sourced, plus an API. GalaxyWarden Signals →
A staff address in a leak usually means a third party was breached, not you — check your own domain’s exposure. Exposure Monitoring →
Report details & sourcing
Related breaches
UBL data leak reports: six accounts, Rs 10.45 million, no bank confirmation
UBL has not publicly confirmed this case. Reporting on a Lahore High Court bail order describes alle…
Is the Carhartt data breach real? What the 12.9 million-email dump means
In August 2026 a hacking group posted files it said were Carhartt’s. A researcher later counted abou…
Facebook — 509 Million Phone Numbers Tied to Real Names (2019, published 2021)
Roughly 20% of Facebook made freely downloadable in April 2021, scraped through a contact-import wea…