Phishing Scams
Fraudsters use unsolicited emails, messages and suspicious links to obtain personal or financial information.
Fraud Mitigation
Credentis’s Zero-Secret Authorization means there is nothing for the scammer to steal, while its Context-Bounded Authorization mitigates major common financial frauds.
Zero-Secret.
Context-Bounded.
SIM-Aware.
Fraudsters use unsolicited emails, messages and suspicious links to obtain personal or financial information.
Victims are deceived or manipulated into transferring money to fraudulent recipients.
Fraudsters impersonating trusted institutions attempt to obtain PINs, passwords, OTPs and other financial information.
Unsolicited messages direct customers to malicious links under the pretext of updating personal credentials.
Fraudsters imitate messages associated with government financial-support programs to deceive eligible individuals.
Promises of quick returns or offers that appear too good to be true are used to induce disclosure or payment.
Supporting Evidence
NCCIA reported that suspects impersonated bank officials and others to obtain OTPs, banking credentials and sensitive information before fraudulently transferring funds.
The fraud depended on something the victim could be deceived into giving away.
Phishing, social engineering, credential theft, malicious links and impersonation exploit the ability to steal or manipulate information used to authorize financial transactions.
Zero-Secret
Nothing for the scammer to steal.
Context-Bounded
Real-time, in-session authorization bound to the transaction being authorized.
See the Difference

482731
Authorization Secret
482731 is the authorization secret — a transferable artifact proven to be stolen, intercepted or socially engineered from customers in real-world financial fraud.
Real-Time · In-Session

310991
Not an Authorization Secret
310991 is not an authorization secret. Intercepting it does not transfer the authorization — the token is unusable outside that authorization session.
SIM-Swap Fraud
Primary Control Behavior
When the SIM associated with the registered mobile number changes, Credentis blocks further authorizations until the account holder completes biometric verification with the bank.
Banking Context
Digital banking relies heavily on the account holder’s registered mobile number and mobile phone. Banks associate both with the customer’s digital banking account, but they are not capable of mandating the registration of the SIM card itself.
Registered
Mobile Number
Registered
Mobile Phone
SIM Change
Detected
Trusted Mobile-Phone
Relationship Changed
Authorizations
Blocked
Bank Biometric
Verification
A changed SIM changes the trusted mobile-phone relationship.
PKR 10.45 million · August 2026
Six customers were reportedly affected in a fraud involving compromised banking information and duplicate SIM issuance.
PKR 8.5 million · October 2025
A duplicate SIM was reportedly issued without his biometric verification, followed by more than 100 unauthorized transactions.
Nationwide · February 2025
Authorities seized thousands of illegally used international SIMs associated with criminal activity including financial fraud.
December 2025
Authorities recovered 150 SIMs and five BVS devices following allegations involving unauthorized SIM issuance.
Nothing for the scammer to steal.
The authorization process does not depend on an authorization secret that can be stolen, intercepted, forwarded, relayed or socially engineered from the customer.
Real-time, in-session authorization bound to the transaction being authorized.
The customer authorizes within the live authorization session, with the authorization bound to the specific transaction being authorized.
Credentis treats a SIM change as a change of mobile phone.
When the SIM associated with the registered mobile number changes, Credentis blocks further authorizations until the account holder completes biometric verification with the bank.
Every Credentis authorization produces structured evidence supporting subsequent review, investigation and reconstruction.