← Back to Pakistan Cyber Tour

Annex 09 — Federal Government Digital Infrastructure

Pakistan OSINT Operation — 01 March 2026 — NADRA • NTC • NITB • FBR • SBP • PTA • SUPARCO • HEC

Pakistan's federal digital infrastructure is centralized around a small number of critical systems managing national identity, government telecommunications, tax revenue, and citizen services for 220+ million people. During the Pakistan-Afghanistan war, virtually all of these systems are offline or access-restricted — but their architecture, attack surface, and historical breach data remain fully documented from pre-war reconnaissance.

1. NADRA — National Database & Registration Authority

NADRA manages the national identity database for 220+ million Pakistani citizens, including Computerized National Identity Cards (CNIC/NICOP), biometric data (fingerprint and facial), voter registration, and citizen verification services.

Wartime Platform Status

PlatformURLPurposeStatus
Pak-ID Appid.nadra.gov.pkNational SSO (OAuth 2.0 + OIDC)500 — "URL blocked"
Nishan APInishan.nadra.gov.pkDeveloper API platform403 — Access Denied
e-Sahulatesahulat.nadra.gov.pkFranchise network (12,000+ locations)DOWN
e-Serviceseservices.nadra.gov.pkOnline citizen servicesDOWN
Digital IDnadra.gov.pk/digitalIdDigital ID portal404

Nishan API Stack — Documented Capabilities

APIFunctionAuth Required
VerisysDemographic verification (name, DOB, address vs CNIC)Company credentials + API key
BiosysBiometric fingerprint verification against NADRA databaseCompany credentials + API key
Multi-biometricFingerprint + facial recognition combinedCompany credentials + API key
Proof-of-LifeLiveness detection (anti-spoofing)Company credentials + API key
Batch VerificationBulk CNIC verification for enterpriseCompany credentials + API key
SSOSingle sign-on integration for third-party appsOAuth 2.0 + OIDC

CNIC Number Structure — Intelligence Value

Every Pakistani Computerized National Identity Card number encodes geographic and demographic information in a predictable 13-digit format:

Format: ABCDE-XXXXXXX-M  (13 digits total)

Position 1:    Province code
               1=KPK  2=FATA  3=Punjab  4=Sindh  5=Balochistan  6=Islamabad  7=Gilgit-Baltistan

Positions 2-5: Division → District → Tehsil → Union Council (hierarchical)
Positions 6-12: Family tree identifier (sequential within locality)
Position 13:   Gender (odd = male, even = female)

A CNIC number alone reveals the holder's province, division, district, tehsil, union council, family lineage number, and gender — enabling geographic correlation and demographic profiling from ID numbers alone.

Historical Breaches

IncidentDateImpact
NADRA Insider Breach2019–2024 (disclosed 2024)2.7M citizen records stolen by NADRA employees in Karachi, Multan, Peshawar offices; sold on dark web to buyers in Argentina and Romania; fraudulent IDs issued to Afghan nationals
Afghan Cyber Army2025100 high-profile .gov.pk sites defaced; NADRA homepage replaced with message about Afghan refugees

2. NTC — National Telecommunication Corporation

NTC provides telecommunications services to Federal and Provincial Governments, the Armed Forces, and defense projects. Its webmail system serves as the email backbone for the entire Pakistani federal government.

Wartime Service Status

ServiceURLStatus
Main Sitentc.net.pkIntermittent
Cloud/Data Centercloud.gov.pkDOWN
Domain Registrationregister.ntc.net.pkDOWN
Government Webmail (Zimbra)mail.ntc.net.pkDOWN
PKI Portalntc.pki.gov.pk503 Service Unavailable
Single Point of Failure: mail.ntc.net.pk (Zimbra) is the email system for the entire Pakistani federal government. Its wartime outage disrupts inter-agency communication across all ministries. If restored and compromised, a single Zimbra instance would provide access to federal government email for every ministry simultaneously.

NTC Services Portfolio

3. NITB — National Information Technology Board

NITB is responsible for digitizing Pakistan's government operations at federal scale.

Scale

Key Platform Status

PlatformURLPurposeStatus
Central Dashboardcd.nitb.gov.pkDigital services monitoring dashboardDOWN
Login Portalbit.nitb.gov.pkGovernment authentication gatewayDOWN
PMRRPpmrrp.nitb.gov.pkProject management and reportingDOWN
Pakistan Citizen Portalweb.citizenportal.gov.pkFederal/provincial complaints routingAccessible (wartime)

Upcoming: DEEP Super App

The Digital Economy Enhancement Project (DEEP), funded by the World Bank and led by NADRA under the Ministry of Interior, is a planned unified gateway for all federal and provincial services. As of February 2026, it was advancing toward launch — the war has since interrupted this timeline.

4. FBR — Federal Board of Revenue

FBR manages Pakistan's tax revenue collection through the IRIS 2.0 (Integrated Revenue Information System) and the PRAL API for enterprise bulk filing.

ServiceURLStatus
IRIS Portaliris.fbr.gov.pkDOWN
Downloadsdownload1.fbr.gov.pkDOWN
PRAL APIpral.com.pkDOWN

PRAL API capabilities (documented pre-war): Bulk income tax return filing, withholding statement submission, bulk sales tax invoice submission, POS integration, data validation, IP whitelisting + security tokens, sandbox testing environment.

5. Other Critical Infrastructure

SBP — State Bank of Pakistan

ServiceURLStatus / Notes
Main Sitesbp.org.pkDOWN
EasyDataeasydata.sbp.org.pk301 → Oracle APEX behind MS IIS ARR/3.0 + Cloudflare; APIs return 401
RaastUPI-like instant payment system (status unknown)

PTA — Pakistan Telecom Authority

ServiceURLStatus
DIRBSdirbs.pta.gov.pkDevice identification system
Complaintscomplaint.pta.gov.pkDOWN
WMSwms.pta.gov.pkWeb monitoring system

HEC — Higher Education Commission

FindingDetail
Main Sitehec.gov.pk — 301 redirect to www
ePortaleportal.hec.gov.pk — HTTP only, 302 redirect
.git/HEAD probehec.gov.pk/.git/HEAD returns 500 (not 404) — server-side error suggests a Git repository exists on the server

A 500 response on /.git/HEAD rather than a 404 is a significant indicator that a Git repository may be present on the production server. If the .git/ directory is accessible, it could expose full source code, commit history, credentials in configuration files, and internal API endpoints.

SUPARCO — Space & Upper Atmosphere Research Commission

ServiceURLStatus
Main Sitesuparco.gov.pk200 OK (Apache, HTTPS)
Disaster GISdisasterwatch.sgs-suparco.gov.pkHTTP only (no TLS)

6. PKI Infrastructure

NTC manages Pakistan's government PKI (Public Key Infrastructure). Its wartime outage has broader consequences beyond email:

ServiceURLStatus
PKI Portalntc.pki.gov.pk503
Code Signing Repositoryntc.pki.gov.pk/repository/Code_Signing_Certificate.html503

7. CMS & Framework Distribution

CMS/FrameworkSites IdentifiedExamples
WordPress3+QAU, Balochistan, SIT Balochistan
Drupal2+LUMS, AIOU
ASP.NET / IIS2+Pakistan Post (ep.gov.pk), HEC
Oracle APEX1SBP EasyData
Laravel (PHP)1UOS (University of Sargodha)
CKAN1opendata.com.pk

8. Network Infrastructure

MetricValue
Total ASNs213
Total IPs5,646,592 (~5.7 million addresses)
Largest ISPPakistan Telecommunication Company (AS17557)
Global IP Ranking#51 / 249 countries

9. Historical Breach Timeline

DateIncidentImpact
2019–2023NADRA insider data theft2.7M citizen records stolen across 3 offices
2024NADRA breach public disclosureData confirmed sold to dark web buyers in Argentina, Romania
2025Global credential breach180M Pakistani internet user credentials exposed
2025SIM data leakFederal ministers and officials' call/SIM metadata leaked
2025Afghan Cyber Army campaign100 high-profile .gov.pk sites defaced simultaneously
2025Cloudflare outage cascading failureNationwide service disruption (heavy CF dependency)

10. Post-Wartime Priority Targets

When Pakistan's infrastructure comes back online after the conflict, the following represent the highest-value targets based on this reconnaissance assessment, ranked by intelligence yield and breach potential.

PriorityTargetRationale
#1mail.ntc.net.pk (Zimbra)All federal government email on one system — total communications access
#2nishan.nadra.gov.pkNational identity API — biometric verification for 220M citizens
#3iris.fbr.gov.pkTax revenue system — financial data for all Pakistani taxpayers
#4cloud.gov.pkNTC Tier-III data center — federal data hosting
#5web.citizenportal.gov.pkCitizen complaints across all agencies — internal routing data
#6hec.gov.pk (/.git/HEAD)Potential source code disclosure via exposed .git directory
#7easydata.sbp.org.pkState Bank financial data (Oracle APEX) — economic intelligence
#8mofa.gov.pkForeign Affairs Ministry — no WAF detected