NADRA is Guarding Identities on Cryptography with a Shelf Life

September 11, 2026
4 min read
A conceptual digital illustration featuring a dense, clustered mass of retro data media—including floppy disks, cassette tapes, ID cards with fingerprints, and documents—tethered to an ornate, antique skeleton key. The entire assemblage is centered on a solid red circular background against a dark backdrop.

A stolen password can be changed within the hour. A stolen fingerprint belongs to its owner for life, which is what makes the cryptography around NADRA’s biometric vault the most consequential in the country, and the least publicly accountable.

There is a category of secret that cannot be reset, and NADRA holds most of Pakistan’s supply of it. A compromised password is an inconvenience that a user fixes in minutes, whereas a compromised fingerprint, iris scan, or facial template stays compromised for the natural life of the person it belongs to. NADRA’s database of roughly 240 million identity and biometric records is therefore the single highest-value target in the national digital estate, and it is also the one whose cryptographic protections are documented least in public. That combination is what this article is about.

Begin with what is on the record, because the record is not reassuring. A joint investigation team led by a senior Federal Investigation Agency officer reported to the Interior Ministry in early 2024 that the credentials of 2.7 million citizens had been compromised between 2019 and 2023, with insider involvement traced to offices in Karachi, Multan, and Peshawar, and copies of the data surfacing as far away as Argentina and Romania. NADRA dismissed several employees and confirmed the findings publicly later that year. In May 2025, Pakistan’s national CERT warned that login credentials for more than 180 million users tied to local services had appeared in a global dump assembled by information-stealing malware. These are not identical incidents, and it would be unfair to lay every leak at NADRA’s door, but together they establish that the corpus is both attractive and reachable.

What NADRA publishes about the cryptography guarding that corpus is close to nothing. Its public communications centre on warnings against unofficial identity apps and on the security upgrades to its Pak Identity platform, rather than on any stated standard for encryption at rest or key management. In the ordinary run of things a citizen would not need those details, but the absence becomes a governance problem once you set it against the quantum timeline. NIST finalised its post-quantum standards in 2024, the United States and European Union have both put migration on a legal clock running to 2030 and 2035, and biometric data is the textbook case for the harvest-now-decrypt-later threat, because its value does not decay while an adversary waits for the hardware to mature.

The legal scaffolding that ought to force the question into the open is still missing. As of mid-2026 Pakistan has no enacted comprehensive data-protection law, the Personal Data Protection Bill has moved between draft and redraft without passage, and the versions circulated largely exempt state agencies from their strictest provisions. NADRA’s Digital Identity Regulations of 2025 gave digital credentials full legal standing and launched a QR-based identity, which expands the surface area of the system without publicly expanding the account of how it is defended. None of NADRA’s published material references post-quantum cryptography, and the national cryptographic standard it is expected to comply with by 2028 contains no post-quantum requirement to comply with.

The way out does not begin with a migration, which would be premature, but with an honest measurement. NADRA should commission an external cryptographic review of the biometric corpus, scoped specifically to answer one question: is this data protected against an adversary who records it now and decrypts it later. If the answer is that the archive relies on RSA or elliptic-curve key wrapping, as most systems of its age do, then the review should set out a costed re-encryption path, keeping AES-256 for the data at rest while moving the key-management layer to a post-quantum scheme such as ML-KEM. A modest and immediate first step, requiring no new technology at all, would be for NADRA to publish its at-rest encryption baseline to Parliament, so that the body accountable to citizens can see what protects the most sensitive database the state maintains on their behalf.

Biometric data is a promise the state makes to its citizens that their identity is safe in its keeping, and a promise with no expiry is only as durable as the cryptography behind it. The next piece looks at the Pakistan Telecommunication Authority, and at the encryption rules that govern the pipes every one of these systems runs through.

Sourcing:

  • Federal Investigation Agency (FIA): Joint investigation team report on the 2019-2023 biometric credential breach (2024).
  • National Cybersecurity: PKCERT advisory regarding global credential dumps (May 2025).
  • Regulatory Frameworks: NADRA Digital Identity Regulations (2025) and the current draft status of the Personal Data Protection Bill (2026).
  • Global Cryptographic Standards: NIST FIPS 203/204/205; US Executive Order 14412; EU NIS Post-Quantum Roadmap.
  • Editorial Note: Certain dark-web data sale claims referenced in broader industry discussions remain independently unverified by Headline Recorder.
Muhammad Shaheer Bin Junaid
Written by

Muhammad Shaheer Bin Junaid is an applied cryptographer and security researcher working on post-quantum encryption, the migration toward it, and the attacks that test whether these systems actually hold. Alongside his research, he builds real systems, and brings an operator’s eye from years of running his own companies. His focus is what quantum-safe security means for the parts of the world the conversation tends to leave out. The author can be reached at contact@mshaheerbjunaid.com.