The Lahore High Court (LHC) has officially recognized confidential bank customer data as “property” under the law, emphasizing that employees who exploit their official access to such information may face criminal breach of trust charges. This landmark ruling emerged from a cyber banking fraud case involving the illicit use of customer data, issuance of counterfeit SIM cards, and fraudulent transfers totaling over Rs104 million from multiple bank accounts.
Justice Tariq Saleem Sheikh delivered a detailed 19-page judgment on Friday while hearing post-arrest bail applications submitted by the accused individuals. The court denied bail to the bank employee Muhammad Atif but granted post-arrest bail to Muhammad Usman, a SIM franchise owner, on the condition of Rs1 million surety bonds.
The judgment highlighted that in the context of contemporary banking, access to customers’ confidential information is tantamount to controlling their financial assets. Consequently, unauthorized use of such data is considered a serious offense. The court further clarified that in cyber banking fraud cases, the involvement of each accused must be evaluated independently based on the evidence presented.
There was sufficient prima facie evidence indicating that Atif had accessed sensitive customer data and was implicated in the fraudulent activities, justifying the rejection of his bail request. The case was initially registered by the National Cyber Crime Investigation Agency (NCCIA) following a complaint lodged by the Pakistan Telecommunication Authority (PTA).
Investigations revealed that confidential banking data was leaked and exploited to obtain fake SIM cards registered in the names of legitimate customers. These SIM cards were then used to facilitate the unauthorized transfer of Rs104 million from the accounts of six individuals.
During proceedings, Usman’s legal counsel argued that their client neither issued the fake SIM cards nor had any incriminating devices or proceeds of crime been recovered from him. Meanwhile, the defense for the bank employee maintained that simply having access to bank records did not establish criminal responsibility.
The prosecution, however, asserted that the case involved a coordinated cyber banking fraud in which each accused played a distinct and crucial role. It was alleged that Atif misused his access to confidential banking information to aid the fraudulent scheme, while the leaked data enabled the issuance of counterfeit SIM cards.
While granting bail to Usman, the court noted the necessity for further investigation to ascertain the extent of direct evidence against him. The bail was granted under surety bonds of Rs1 million, with the trial and investigation set to proceed as per legal procedures.
Additionally, the judgment observed that the accused could face prosecution not only under the Prevention of Electronic Crimes Act (Peca) but also under pertinent sections of the Pakistan Penal Code, reflecting the gravity of the offenses involved.