Invisible risks

Published
0
The writer is a banker.
The writer is a banker.

ON the night of Feb 5, 2016, hackers pushed 35 fraudulent payment instructions through the SWIFT interbank messaging system. By the time Bangladesh Bank detected the breach, $81 million had left its account at the New York Federal Reserve and landed in the Philippines. Most of it was never recovered. There was no break-in, no border crossed, no vault touched — the heist happened entirely through a screen.

But this is not only a story about central banks. The same battle is now fought daily on the phone in your pocket. It is the call from someone claiming to be ‘from your bank’, warning that your card is being blocked and asking you to ‘verify’ your details. It is the fake loan app, the link that looks exactly like your bank’s website but is not. The Bangladesh Bank robbers needed months of planning to trick a central bank. Today’s fraudster needs only a phone call and 30 seconds of your trust.

The reason this matters to every Pakistani household is simple: our money now lives on digital rails. Nine in 10 retail payments in Pakistan are made digitally — the salary that arrives in an account, the pension drawn from an ATM, the remittance sent from Dubai, the utility bill paid from a mobile app, the shopkeeper’s QR code. In a single quarter, these transactions now approach Rs170 trillion in value. This is a genuine triumph of convenience and financial inclusion. But it also means that when the rails are attacked, it is not an ‘IT problem’ — it is your salary and your savings that are on the line.

As mobile banking grows, so does the attack surface.

And the attackers are getting smarter. AI, the same technology banks use to detect fraud, now helps criminals write flawless fake messages, clone voices and mimic official websites. Globally, nearly three in four people report that they, or someone close to them, were touched by cyber-enabled fraud last year. Pakistan is no exception: the credentials of more than 180m Pakistani internet users surfaced in a global data breach, and malicious software targeting banking apps on smartphones rose by more than half in a year. As mobile banking grows, so does the attack surface — and unlike a bank branch, a smartphone has no security guard.

Banks themselves remain the most attractive target, for an obvious reason: they hold valuable information and they can move money. Global studies put the average cost of a single breach at around $5m — higher in finance — while institutions that invest ahead of the curve lose far less when trouble comes. The principle applies to a bank exactly as it applies to a household: prevention always costs less than loss.

There is encouraging news. Pakistan has climbed from 79th to 29th on the ITU’s Global Cybersecurity Index in just three years. The State Bank has set up a dedicated Cyber Risk Management Depart­ment, launched Cyber Shield 2025-30, and this January conducted the country’s first industry-wide cybersecurity drill across 34 financial institutions — a recognition, at last, that an attack on one bank is a threat to all.

Consider what disruption would actually feel like. If even a tenth of digital payments stopped for two days — apps down, cards declined, QR codes dead — transactions worth roughly Rs100 billion could be affected. The queue outside the ATM would be the least of it: shopkeepers unpaid, salaries delayed, and a corrosive question in people’s minds — is my money safe on this phone? That question, repeated often enough, would push people back towards cash and undo a decade of hard-won progress. Trust takes years to build and one bad weekend to lose.

The task for Pakis­tan’s banks, therefore, is to move beyond minimum compliance towards genuine resilience. Cybersecurity must sit on the boardroom agenda alongsi­­de credit and liquidity risk — with continuous monitoring, tested defences, scrutiny of third-party vendors, and staff trained as rigorously as tellers once were trained to spot forged cheques. Banks, regulators and technology firms must also cooperate far more closely, because criminals collaborate freely while defenders too often work alone. The benchmark must be the attack withstood.

But the reader has a role too, and it is decisive. Remember three things. Your bank will never — not once, not ever — call to ask for your PIN, password or the one-time code sent to your phone; anyone who does is a thief. A prize you never entered for is bait, and an offer too good to be true always is. And a moment’s pause before clicking a link is the cheapest security investment ever invented. The strongest firewall in the country is an alert customer.

Bangladesh Bank lost $81m in a single night because attackers found an opening. The question — for every bank, and for every one of us holding a phone — is not whether such an opening exists. The question is whether we find it before they do.

The writer is a banker.

Published in Dawn, September 26th, 2026

Opinion

Editorial

Kashmir unresolved
Updated 30 Sep, 2026

Kashmir unresolved

The just solution lies in India addressing the issue through a trilateral dialogue involving the legitimate representatives of the Kashmiri people and Pakistan.
Water shortage
30 Sep, 2026

Water shortage

THAT the country is entering the Rabi season with an anticipated water shortage of nearly 25pc, the lowest carryover...
Young hearts
30 Sep, 2026

Young hearts

THE observance may have passed, but the message of World Heart Day should not fade with it. The occasion is a useful...
Terror and politics
Updated 29 Sep, 2026

Terror and politics

There is an urgent need to tone down the rhetoric and tackle terrorism as a collective challenge for both the affected provinces and the federation.
Watching the glaciers
29 Sep, 2026

Watching the glaciers

THE latest signs from Pakistan’s mountains are worrying. Suparco says the number of unfrozen glacial lakes it...
Dangerous agenda
29 Sep, 2026

Dangerous agenda

AS the world remains fixated on the US-Iran conflict, elsewhere in the Middle East, Israel is consolidating its grip...