The Lahore High Court has ruled that customer information entrusted to a bank can constitute “property” under Pakistani law and that its dishonest disclosure or misuse may amount to criminal breach of trust. The ruling was issued by Justice Tariq Saleem Sheikh while deciding bail applications in a multi-million-rupee SIM swap fraud case involving a private bank employee and a telecom franchise operator.
The case was registered by the National Cyber Crime Investigation Agency over allegations involving the fraudulent issuance of duplicate SIM cards using customers’ Computerised National Identity Cards and fingerprints. The investigation also concerned unauthorized transfers amounting to Rs10.45 million from the accounts of six customers of a private bank.
Justice Tariq Saleem Sheikh examined the legal status of customer information maintained by banks, including account details and registered mobile numbers. The court observed that such information falls within the definition of “data” under the Prevention of Electronic Crimes Act. The judgment noted that Section 27(2) of the Prevention of Electronic Crimes Act expressly treats such data as “property” for offences relating to property under the Pakistan Penal Code.
The court further held that when customer data is entrusted to a bank employee or placed under the employee’s control, its dishonest disclosure or unauthorized use in support of a fraudulent scheme may constitute criminal breach of trust. The judgment also linked the protection of customer information to the confidentiality obligations arising from a banking employment relationship and the provisions of Section 33A of the Banking Companies Ordinance, 1962.
The ruling addresses the growing importance of customer information in digital banking. Justice Sheikh observed that modern banking relies heavily on electronic systems through which customer funds are accessed, verified and protected. In this environment, control over critical customer information can, in practical terms, provide control over access to a customer’s money.
The court clarified, however, that Section 409 of the Pakistan Penal Code does not automatically apply to every employee working for a bank. Section 409 concerns criminal breach of trust committed by a public servant, banker, merchant or agent. Justice Sheikh said a functional test must instead be applied to determine whether an employee falls within the provision.
According to the judgment, Section 409 can apply where a bank employee is entrusted with or exercises control over customer funds or customer data that is used for access, verification, authentication or banking transactions as part of the employee’s banking responsibilities. Employees who have only incidental or casual access to such information would not automatically fall within the scope of the provision.
The court reached this conclusion while considering the case against Muhammad Atif, a private bank employee. Justice Sheikh noted that investigation records, the bank’s internal fraud reports and account-access logs collectively provided sufficient incriminating material against Atif. The investigation alleged that he disclosed customers’ registered mobile numbers, which subsequently facilitated the SIM swap fraud.
Based on the material available at the investigation stage, the court found that Section 409 of the Pakistan Penal Code was prima facie attracted in Atif’s case. Justice Sheikh therefore dismissed the bank employee’s bail application.
The court adopted a different position regarding Muhammad Usman, who allegedly operated at the cellular company franchise from which the duplicate SIM cards were issued. Although the prosecution claimed that Usman managed the franchise, Justice Sheikh found that the available evidence did not sufficiently connect him with the disputed SIM activations, alleged manipulation of the biometric verification system or abetment of the dishonest use of banking property or customer data.
The court determined that the allegations against Usman required further inquiry. Justice Sheikh consequently granted him post-arrest bail against surety bonds of Rs1 million.
The ruling places particular significance on the role of customer information in modern banking and digital financial transactions. By recognizing qualifying customer data as property under the relevant legal framework, the judgment establishes that unauthorized use of information entrusted to banking personnel can have consequences beyond internal disciplinary or confidentiality issues where the circumstances meet the requirements of criminal law.
The case also highlights the connection between banking data, mobile identity verification and digital financial fraud. Registered mobile numbers, identity documents and biometric information can play an important role in authenticating customers and accessing financial services. The court’s observations therefore underline the responsibility of banking personnel who have functional control over information used to verify or facilitate banking transactions.
The Lahore High Court’s ruling does not establish that every instance of employee access to customer information constitutes criminal breach of trust. Instead, the judgment emphasizes the nature of the employee’s responsibilities, the degree of control exercised over customer funds or critical data and the manner in which the information was allegedly used. The distinction formed a central part of the court’s separate decisions on the two accused individuals.
Follow the PakBanker Whatsapp Channel for updates across Pakistan’s banking ecosystem.



