The article “Invisible risks”, authored by Zafar Masud was published in on September 26, 2026 —
Invisible risks — Overview
The article was published in Dawn by Zafar Masud, a banker, as an opinion piece highlighting the emerging threats associated with digital banking in Pakistan. It is relevant due to the increasing frequency of cyberattacks targeting financial institutions and individuals alike. The overall tone is urgent and cautionary, urging both banks and consumers to prioritize cybersecurity measures. Zafar Masud’s role as the writer lends credibility to the discussion, as he draws on his expertise to stress the importance of vigilance against fraud in a rapidly digitizing economy. His inclusion is significant, as it connects expert insight with public awareness of financial security, reinforcing the message that every individual shares responsibility for their digital safety. The broader narrative suggests that while digital banking enhances accessibility and convenience, it also introduces substantial risks that must be managed collectively by institutions and consumers to prevent financial disasters.
Article Summary
This article discusses the increasing risks in digital banking, drawing attention to the $81 million theft from Bangladesh Bank in 2016 and the rise of cyber-enabled fraud in Pakistan. It emphasizes the need for enhanced cybersecurity in financial institutions as digital payments surge, outlining preventive measures banks must take and the crucial role consumers play in protecting themselves from fraud. It concludes that the success of digital banking relies on trust and proactive security measures against evolving cyber threats.
Invisible risks — Article by Zafar Masud
By Zafar Masud. published in on September 26, 2026
ON the night of Feb 5, 2016, hackers pushed 35 fraudulent payment instructions through the SWIFT interbank messaging system. By the time Bangladesh Bank detected the breach, $81 million had left its account at the New York Federal Reserve and landed in the Philippines. Most of it was never recovered. There was no break-in, no border crossed, no vault touched — the heist happened entirely through a screen.
But this is not only a story about central banks. The same battle is now fought daily on the phone in your pocket. It is the call from someone claiming to be ‘from your bank’, warning that your card is being blocked and asking you to ‘verify’ your details. It is the fake loan app, the link that looks exactly like your bank’s website but is not. The Bangladesh Bank robbers needed months of planning to trick a central bank. Today’s fraudster needs only a phone call and 30 seconds of your trust.
The reason this matters to every Pakistani household is simple: our money now lives on digital rails. Nine in 10 retail payments in Pakistan are made digitally — the salary that arrives in an account, the pension drawn from an ATM, the remittance sent from Dubai, the utility bill paid from a mobile app, the shopkeeper’s QR code. In a single quarter, these transactions now approach Rs170 trillion in value. This is a genuine triumph of convenience and financial inclusion. But it also means that when the rails are attacked, it is not an ‘IT problem’ — it is your salary and your savings that are on the line.
As mobile banking grows, so does the attack surface.
And the attackers are getting smarter. AI, the same technology banks use to detect fraud, now helps criminals write flawless fake messages, clone voices and mimic official websites. Globally, nearly three in four people report that they, or someone close to them, were touched by cyber-enabled fraud last year. Pakistan is no exception: the credentials of more than 180m Pakistani internet users surfaced in a global data breach, and malicious software targeting banking apps on smartphones rose by more than half in a year. As mobile banking grows, so does the attack surface — and unlike a bank branch, a smartphone has no security guard.
Banks themselves remain the most attractive target, for an obvious reason: they hold valuable information and they can move money. Global studies put the average cost of a single breach at around $5m — higher in finance — while institutions that invest ahead of the curve lose far less when trouble comes. The principle applies to a bank exactly as it applies to a household: prevention always costs less than loss.
There is encouraging news. Pakistan has climbed from 79th to 29th on the ITU’s Global Cybersecurity Index in just three years. The State Bank has set up a dedicated Cyber Risk Management Department, launched Cyber Shield 2025-30, and this January conducted the country’s first industry-wide cybersecurity drill across 34 financial institutions — a recognition, at last, that an attack on one bank is a threat to all.
Consider what disruption would actually feel like. If even a tenth of digital payments stopped for two days — apps down, cards declined, QR codes dead — transactions worth roughly Rs100 billion could be affected. The queue outside the ATM would be the least of it: shopkeepers unpaid, salaries delayed, and a corrosive question in people’s minds — is my money safe on this phone? That question, repeated often enough, would push people back towards cash and undo a decade of hard-won progress. Trust takes years to build and one bad weekend to lose.
The task for Pakistan’s banks, therefore, is to move beyond minimum compliance towards genuine resilience. Cybersecurity must sit on the boardroom agenda alongside credit and liquidity risk — with continuous monitoring, tested defences, scrutiny of third-party vendors, and staff trained as rigorously as tellers once were trained to spot forged cheques. Banks, regulators and technology firms must also cooperate far more closely, because criminals collaborate freely while defenders too often work alone. The benchmark must be the attack withstood.
But the reader has a role too, and it is decisive. Remember three things. Your bank will never — not once, not ever — call to ask for your PIN, password or the one-time code sent to your phone; anyone who does is a thief. A prize you never entered for is bait, and an offer too good to be true always is. And a moment’s pause before clicking a link is the cheapest security investment ever invented. The strongest firewall in the country is an alert customer.
Bangladesh Bank lost $81m in a single night because attackers found an opening. The question — for every bank, and for every one of us holding a phone — is not whether such an opening exists. The question is whether we find it before they do.
The writer is a banker.
Published in Dawn, September 26th, 2026
Authored by Zafar Masud. Originally published in on September 26, 2026