NADRA is Guarding Identities on Cryptography with a Shelf Life

A stolen password can be changed within the hour. A stolen fingerprint belongs to its owner for life, which is what makes the cryptography around NADRA’s biometric vault the most consequential in the country, and the least publicly accountable.
There is a category of secret that cannot be reset, and NADRA holds most of Pakistan’s supply of it. A compromised password is an inconvenience that a user fixes in minutes, whereas a compromised fingerprint, iris scan, or facial template stays compromised for the natural life of the person it belongs to. NADRA’s database of roughly 240 million identity and biometric records is therefore the single highest-value target in the national digital estate, and it is also the one whose cryptographic protections are documented least in public. That combination is what this article is about.
Begin with what is on the record, because the record is not reassuring. A joint investigation team led by a senior Federal Investigation Agency officer reported to the Interior Ministry in early 2024 that the credentials of 2.7 million citizens had been compromised between 2019 and 2023, with insider involvement traced to offices in Karachi, Multan, and Peshawar, and copies of the data surfacing as far away as Argentina and Romania. NADRA dismissed several employees and confirmed the findings publicly later that year. In May 2025, Pakistan’s national CERT warned that login credentials for more than 180 million users tied to local services had appeared in a global dump assembled by information-stealing malware. These are not identical incidents, and it would be unfair to lay every leak at NADRA’s door, but together they establish that the corpus is both attractive and reachable.
What NADRA publishes about the cryptography guarding that corpus is close to nothing. Its public communications centre on warnings against unofficial identity apps and on the security upgrades to its Pak Identity platform, rather than on any stated standard for encryption at rest or key management. In the ordinary run of things a citizen would not need those details, but the absence becomes a governance problem once you set it against the quantum timeline. NIST finalised its post-quantum standards in 2024, the United States and European Union have both put migration on a legal clock running to 2030 and 2035, and biometric data is the textbook case for the harvest-now-decrypt-later threat, because its value does not decay while an adversary waits for the hardware to mature.
The legal scaffolding that ought to force the question into the open is still missing. As of mid-2026 Pakistan has no enacted comprehensive data-protection law, the Personal Data Protection Bill has moved between draft and redraft without passage, and the versions circulated largely exempt state agencies from their strictest provisions. NADRA’s Digital Identity Regulations of 2025 gave digital credentials full legal standing and launched a QR-based identity, which expands the surface area of the system without publicly expanding the account of how it is defended. None of NADRA’s published material references post-quantum cryptography, and the national cryptographic standard it is expected to comply with by 2028 contains no post-quantum requirement to comply with.
The way out does not begin with a migration, which would be premature, but with an honest measurement. NADRA should commission an external cryptographic review of the biometric corpus, scoped specifically to answer one question: is this data protected against an adversary who records it now and decrypts it later. If the answer is that the archive relies on RSA or elliptic-curve key wrapping, as most systems of its age do, then the review should set out a costed re-encryption path, keeping AES-256 for the data at rest while moving the key-management layer to a post-quantum scheme such as ML-KEM. A modest and immediate first step, requiring no new technology at all, would be for NADRA to publish its at-rest encryption baseline to Parliament, so that the body accountable to citizens can see what protects the most sensitive database the state maintains on their behalf.
Biometric data is a promise the state makes to its citizens that their identity is safe in its keeping, and a promise with no expiry is only as durable as the cryptography behind it. The next piece looks at the Pakistan Telecommunication Authority, and at the encryption rules that govern the pipes every one of these systems runs through.
Sourcing:
- Federal Investigation Agency (FIA): Joint investigation team report on the 2019-2023 biometric credential breach (2024).
- National Cybersecurity: PKCERT advisory regarding global credential dumps (May 2025).
- Regulatory Frameworks: NADRA Digital Identity Regulations (2025) and the current draft status of the Personal Data Protection Bill (2026).
- Global Cryptographic Standards: NIST FIPS 203/204/205; US Executive Order 14412; EU NIS Post-Quantum Roadmap.
- Editorial Note: Certain dark-web data sale claims referenced in broader industry discussions remain independently unverified by Headline Recorder.

