Digital fraud in Pakistan is piling up in the same places where digital transformation is happening to adopt cashless societies, financial institutions are scaled for reach and convenience: through various digital alternate delivery channels such as mobile apps, cards and wallets etc.. As transactional volumes increases the fraudulent complaints are rising as well, compensation payouts are mounting: evidence that too many workflows still miss fraud detection in real time or may be they are post-facto which are cleaned up after the fact.
Pakistan’s central bank, the State Bank of Pakistan (SBP), set out its expectations for digital banking security in 2023, then operationalised them in 2024, requiring free in-app/push/email alerts with complete notification logs for mobile-app transactions. Many institutions are still below that baseline; controls need to live at the point of risk, not in next-day reconciliation.
Some banks have moved to in-session controls that create audit-ready evidence and stop fraud before it hits the customer. Others still post-reconcile, absorbing losses, paying compensation and exposing gaps that regulatory supervisors now scrutinise.
SBP’s liability framework matters here too: banks are expected to compensate customers for unauthorised mobile-app transactions, which puts a premium on alerts, logs and in-session decisions that can be shown later.
The three “V” : Volume, Velocity, Vulnerability
The usage mix concentrates risk. Mobile-based payments rose 22% in value and 16% in volume in Q3 FY25, reaching 1.7 billion transactions worth PKR 27 trillion. Wallet usage also expanded, with 68.5 million active users and 94% of e-commerce checkouts now routed through digital wallets. Registered mobile-banking users continue to climb quarter by quarter, reinforcing where exposure sits.
The Banking Mohtasib, Pakistan’s independent banking ombudsman, has logged a steep rise in fraud-related complaints. In 2024, 27,753 cases were resolved with PKR 1.65 billion in compensation payouts. In the first half of 2025, another 16,006 complaints triggered PKR 882 million in redress.
Bank ABC Partners with Temenos and NdcTech to Implement Next-Generation Core Banking System
Public statements from the ombudsman attribute the surge to “loopholes, laxity and weakness in internal control of banks”, which fraudsters have exploited to deprive thousands of customers of their savings.
That’s why control has to live at the point of risk, and show up in the product, not the paperwork.
Decisions in the journey
Point of risk means the decision lands while the customer is using the service, and the record of that decision stands up later. In practice, that means running expert rules for known patterns alongside adaptive machine-learning models trained on recent behaviour, so unusual activity is flagged before a manual rule exists. The system then reads the moments that matter; such as a new device binding, location based tagging, a first-time payee, a profile change that opens permissions, a higher-value transfer at an unusual hour; and resolves them in context.
Staying two steps ahead: How BPC is shaping the future of payments in Asia-Pacific
When signals are weak, the journey continues. When they’re strong, the session steps up to second factor of authorization without breaking flow. On web, the simplest pattern works best: show a QR on the page, complete the check in the mobile app, return to the same page with the session intact. Today this hand-off is smartphone-first; broader device support is being explored.
The customer experiences one continuous journey. Operators see the full trail on a single screen and record a short, human-readable reason with a timestamp before allowing, pausing, or stopping the action. That one line is what customer care can read back and what investigators, auditors and the ombudsman expect to see.
Evidence is already half the protection. Alerts need to be short, specific and quick, and they need to leave a trail: when the message went out, when it was read, and what the customer did next. Case records should show who did what, when, on which device and channel, alongside the reason tied to the decision.
This is already visible on the ground. This is already visible on the ground. Many banks such as Habib Metropolitan Bank, Askari Bank, Allied Bank and Meezan Bank has already implemented such controls, to not only comply with regulatory push but also to secure massive digital transactions these organizations are processing while enjoying their role among the top tier banks in Pakistan.
Samba Bank, a Pakistan-based commercial bank majority-owned by Saudi National Bank, has routed sensitive actions such as logins, device changes, new payees, profile edits and higher-value payments through a single decision layer that runs while the session is open. Operators work from one console with the full trail and 360 view; confirmed suspicious cases flow back into detection on a regular basis so the model learns, accuracy increases even further.
MCB in Pakistan moved early to harden its digital channels with an AI-driven fraud prevention. The bank now sees cards, accounts, and apps in one view and scores activity in real time, blocking risky behavior as it happens. Link analysis connects transactions, devices, and identities to surface organised fraud patterns. Model adapt as patterns change, with rules covering known cases, resulting in faster fraud control actions, leaner queues, and protection that keeps pace with new threats.
Making resilience routine
Traditional banks need to start treating fraud resilience as strategy, not just compliance upgrade. Boards and supervisors won’t need a catalogue of KPIs to see whether it works. They should not compare their losses with the investment they are making as many silent frauds still remain undetected, creating losses and cannot be account for at this point in time.
They will look for faster, documented decisions measured in split second rather than minutes that prevented fraud and as a result loss of customer loyalty and funds.Such systems should be implemented in house within financial institutions to bring greater response rate, lower latency rather than relying on internet or virtual private networks specially if all on-us and off-us transactions needs to be revalidated against a number of rules which will grow as transactional volumes and fraud scenarios are increasing.
Why now? Liability sits with banks under SBP’s framework, attackers becoming smarter daily, and customer trust is fragile. A strategic approach reduces direct losses and call-centre load, protects customer satisfaction and speeds regulatory audits because every decision is explained and timestamped with frictionless experience to end user.
Furrukh Ali Baig is a senior fintech leader and the Managing Director for Pakistan, Nepal, and Iraq at BPC Banking Technologies. He is a prominent figure in the digital payments and financial services industry, overseeing BPC’s operations, business development, and strategic expansion across these markets. The views expressed are his own and do not necessarily represent those of The Islamabad Telegraph.

