LAHORE: The Lahore High Court (LHC) has ruled that customer data entrusted to a bank constitutes “property” under the law and its dishonest misuse may amount to criminal breach of trust.
Justice Tariq Saleem Sheikh issued the ruling granting post-arrest bail to a telecom franchise operator accused in a multi-million-rupee SIM-swap fraud case while refusing bail to a private bank employee.
The National Cyber Crime Investigation Agency (NCCIA) had registered the case about the alleged fraudulent issuance of duplicate SIMs, using victims’ CNICs and fingerprints and unauthorised transfers of Rs10.45m from six customers’ accounts of the private bank Justice Sheikh maintained that customer information maintained by banks -- including account particulars and registered mobile numbers -- falls within the definition of “data” under the Prevention of Electronic Crimes Act (Peca), and that Section 27(2) of Peca expressly treats such data as “property” for offences relating to property under the Pakistan Penal Code (PPC).
The judge observed that where customer data is entrusted to a bank employee or placed under his dominion, its dishonest disclosure or unauthorised use in furtherance of a fraudulent scheme may amount to criminal breach of trust. He asserted that such conduct would also violate the duties of confidentiality arising from banking employment and was reinforced under Section 33A of the Banking Companies Ordinance, 1962.
Justice Sheikh ruled that in modern banking, customer funds are accessed and protected electronically, and whoever controls the customer’s critical data may, in practical terms, control access to the customer’s money. He clarified that not every bank employee automatically falls within Section 409 PPC (criminal breach of trust committed by a public servant, banker, merchant, or agent). Instead, he said, a functional test must be applied.
“Section 409 is attracted only where an employee is entrusted with, or exercises dominion over, customer funds or customer data used for access, verification, authentication or banking transactions as part of his banking functions. Employees having only incidental or casual access would not fall within its scope,” the judge explains.
With regard to the suspect, Muhammad Atif, the bank employee, the judge noted that investigation records, the bank’s internal fraud reports and account-access logs collectively provided sufficient incriminating material against the suspect. He noted that the investigation alleged that the suspect had disclosed customers’ registered mobile numbers, facilitating the SIM-swap fraud.
Holding that Section 409 PPC was prima facie attracted in the case, the judge dismissed the bail plea of the bank’s employee.
The judge, however, reached a different conclusion regarding the other suspect, Muhammad Usman, who allegedly operated at the cellular company’s franchise from where duplicate SIMs were issued.
The judge observed that although the prosecution claimed Usman managed the franchise, the available evidence did not sufficiently connect him with the disputed SIM activations, the alleged manipulation of the biometric verification system (BVS), or abetment of the dishonest use of banking property or customer data.
The judge said the allegation against Usman required “further inquiry” and granted him post-arrest bail against surety bonds of Rs1m.
Published in Dawn, August 8th, 2026




























