Skip to content
Back to Blog
high severity August 26, 2026 · 5 min read Unverified claim — what this is

UBL data leak and SIM-swap reports: what worried customers should know

If you are a customer of UBL, here’s what is being claimed, and what it would mean for you.

United Bank Limited has not confirmed this case or issued a customer notice about it. Several Pakistani outlets, citing a Lahore High Court order and investigators, report that confidential UBL customer information — including registered mobile numbers — was obtained through insider access and used in a duplicate-SIM scheme. About Rs 10.46 million was allegedly taken from six accounts; the criminal case is still underway.

— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
UBL data leak and SIM-swap reports: what worried customers should know

United Bank Limited has not confirmed this incident. No public statement, support notice or filing from the bank about this specific case was found. What follows is what The Express Tribune, The Nation, Daily Pakistan and TechJuice independently reported from a Lahore High Court written order, a complaint to Pakistan’s telecom regulator, cybercrime investigators, and UBL internal inquiry reports that were given to those investigators — not published for customers.

Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

According to that coverage, complaints in November 2025 said duplicate copies of customers’ mobile numbers had been issued against their national identity cards and then used to move money out of UBL accounts. Two of those replacement SIMs were reportedly issued on 6 November and 9 November 2025; the original SIMs were blocked, new devices were registered on the accounts, and funds were transferred. Investigators reportedly identified six UBL account holders in all. The amount alleged to have been taken is Rs 10,458,500 (about Rs 10.45 million). Some headlines said “Rs 10 crore”; that does not match the court and investigation record those outlets cite. A raid in November 2025 reportedly recovered SIM-related equipment and led to an arrest. A case was registered on 18 November 2025. UBL’s fraud team, as those reports recite from the court file, wrote internal notes dated 30 December 2025 on the six accounts and 29 May 2026 on a larger set of complaints, describing leakage of customers’ confidential information through insider access, including by UBL employees. In August 2026 the high court, according to the same outlets, refused bail for one employee and granted bail to another person subject to further inquiry. Authorities also reportedly said about Rs 10.5 million was recovered in June 2026 and returned to complainants. No trial verdict or conviction has been reported.

This is being told as a story about six people and a court phrase. For you, it is a phone-number story.

The coverage leads with a contained crime: six customers, a rupee total, a raid, and a legal line that customer data can count as “property.” Those points, as reported, appear to be what the court was asked to decide. They are not the part that changes what a UBL customer should do tomorrow morning.

The method described in that same court record, as the outlets retell it, starts one step earlier. Confidential banking information — including the mobile number registered on an account — was reportedly obtained through insider access, not by guessing or by breaking into a public website. That number is the switch. A second SIM in your name means the texts and approval codes meant for you go to someone else. After that, the transfer looks to the bank like you. The six losses are the cases that produced a police file and a bail hearing. They are not, on the reporting we have, a public list of everyone whose record was looked up. The bank’s second internal report, dated 29 May 2026 and recited in court according to those outlets, was described as covering a larger set of complaints. How large, and whether that means more records were accessed or only that more people later complained, has not been published.

That is the honest read, not a claim that every UBL customer is in this file. We do not know who was queried. UBL has not said. The bank’s general posts about SIM scams are not a notice about this case. What an ordinary reader should take from the reporting is narrower and more useful than the headlines: the dangerous object here is the pairing of a real account with the phone number the bank will trust, and that pairing, according to the outlets citing UBL’s own internal reports, was available to people inside the bank.

What to actually expect

  • Do not expect a letter, SMS or app alert from UBL that names this incident. On the available reporting, the bank has not issued a customer-facing notice about it.
  • You will not get a public page where you can type your name or account number and see whether you were in the internal reports. Those reports, as described, went to investigators. A “breach check” elsewhere will not settle this.
  • The near-term signal that matches this case is on your phone and on the account: a replacement SIM you did not ask for, a sudden loss of service, a new device you did not add, or a transfer you did not make. In the reported cases, the money moved after the new SIM and device were already in place.
  • Bail rulings are not a verdict. The outlets describe an investigation and court argument that is still open. Treat “an employee was refused bail” as a legal update, not as proof the bank has finished with the underlying access problem.

What you can and cannot fix

What cannot be undone is the look-up itself. If an employee already opened your account record or copied the mobile number registered on it, that viewing cannot be recalled, and no company can scrub it from the people who saw it. Your national identity number cannot be changed. Nobody can honestly promise to pull this data back, and nobody can honestly tell you, from a public scan, whether your row was one of the ones opened.

What still helps, in order:

  • Confirm you still control the SIM on your UBL account. That is the switch this reported scheme used. If you did not request a new SIM, and you lose service or get a registration message you did not cause, contact your mobile operator and the bank the same day and say you are worried about a duplicate SIM on the number tied to the account.
  • Read the account itself for the next traces this case actually left: transfers you did not make, and devices or numbers added that you do not recognise. That is how the reported thefts showed up once the new SIM was live.
  • Ask your operator, before you need it, what extra checks they will apply before anyone can take out a replacement SIM against your national identity card. The complaints described in court, as reported, began with those replacement SIMs being issued.
  • Shrink the extra personal detail about you that sits in people-search and directory listings. A bank-side note that only ties a name to a registered mobile number becomes much easier to use when it can be joined to listings that add relatives, other phone numbers, employers and old addresses. Those listings, unlike whatever was already viewed inside the bank, can actually be taken down. The leaked or accessed bank record cannot.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

What to do now

Steps that match what this notice says was exposed

Every step below is free and you do it yourself, and none of it depends on UBL.

  1. Tell your bank before you do anything else. Account and routing details are the fastest-moving of the fields in this notice. Call the number on the back of your card rather than any number in an email, and ask them to watch the account and reissue the card.

One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.

Check your exposure
UBL is one listing. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High includes account details that can be misused directly
Disclosed August 26, 2026
Last reviewed August 26, 2026
Affected Unconfirmed
Data exposed Registered mobile numbersConfidential banking informationAccount informationNational ID-linked identity data
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email