Verify any claim · lenz.io
Claim analyzed
Tech“Pakistan’s National Aerospace Science and Technology Park (NASTP) suffered a data leak.”
The conclusion
Open in workbench →Available evidence does not show that NASTP suffered a data leak. Credible reports in the source set describe breaches involving NADRA or unspecified Pakistani government portals, not the National Aerospace Science and Technology Park. The claim appears to misattribute a real Pakistani data-leak story to the wrong institution.
Caveats
- The strongest sources document NADRA-related breaches, not a NASTP breach.
- General reports about exposed government credentials do not establish that NASTP was affected.
- Several low-reliability social-media sources are speculative and do not provide verified attribution.
Fact-check inside the tools you already use
Connect Lenz to ChatGPT, Claude, or WhatsApp and check a claim mid-conversation.
Or create a free account to bookmark this verification and run your own checks.
Sources
Sources used in the analysis
The National Aerospace Science & Technology Park (NASTP) is described as "a Pakistani aerospace and cyberspace technology park established by the Pakistan Air Force." It notes that NASTP's website is nastp.gov.pk but does not mention any data breach, leak, or cybersecurity incident affecting NASTP. The article focuses on institutional background rather than security events.
An investigation has revealed that personal information of more than **2.7 million Pakistanis has been ‘stolen’ from the records of a government-run body that regulates the database of citizens**. A government official said that a team was formed to probe the data leak from the **National Database and Registration Authority (Nadra)** office. The report indicated "that data of more than 2.7 million Pakistanis has been compromised from Nadra’s records between 2019 and 2023" and recommended technology upgrades and proceedings against those responsible for the data breach.
In coverage of the inauguration of NASTP, the report states that "Pakistan Prime Minister Shehbaz Sharif on Friday inaugurated the National Aerospace Science and Technology Park at the Pakistan Air Force (PAF) Base Nurkhan in Rawalpindi." The article describes the objectives of the park and its strategic importance but contains no mention of any data leak, hack, or compromise of NASTP’s systems or data.
Pakistan’s National Cyber Emergency Response Team (PKCERT) issued an advisory warning that the login credentials and passwords of more than 180 million internet users in Pakistan have been stolen in a global data breach. The advisory describes a publicly accessible, unencrypted file with more than 184 million unique account credentials and notes that exposed services include major tech platforms as well as government portals, banking institutions, and healthcare platforms worldwide. The article also recalls that in March 2024 a Joint Investigation Team reported that credentials of 2.7 million citizens had been compromised from the National Database and Registration Authority (Nadra) records between 2019 and 2023, but it does not mention NASTP in connection with these breaches.
A breach listing notes: "Victim | nadra.gov.pk" and identifies the National Database and Registration Authority of Pakistan as the affected organisation in a data breach discovered on March 27, 2025. The entry describes NADRA as "a government agency providing identification, registration, and database management services" and attributes the incident to the threat actor Babuk, with the leak size marked as unknown. The listing does not reference NASTP or the National Aerospace Science & Technology Park as part of this breach.
A report on the Prime Minister inaugurating the Aerospace Science & Technology Park states that "Prime Minister Shehbaz Sharif Friday inaugurated the National Aerospace Science and Technology Park (NASTP) established with the collaboration among the government, international companies and private sector." The content is about the launch, investment, and strategic goals of NASTP and does not reference any data leak or cybersecurity incident involving the park.
An EFE report from Islamabad states that an investigation found personal information of more than 2.7 million Pakistanis had been "stolen" from records of the National Database and Registration Authority (Nadra). A government official said a team was formed to probe "the data leak from the National Database and Registration Authority (Nadra) office" and that data was compromised from Nadra’s records between 2019 and 2023. The report, citing Dawn, adds that Nadra offices in Karachi, Multan, and Peshawar were allegedly involved and that stolen data was sent to Dubai and later sold in Argentina and Romania. NASTP is not mentioned in relation to this scandal.
The Sindh High Court issued notices to federal authorities on a petition seeking investigation into reports about **data breach of 115 million mobile phone users from Pakistan and its sale on the darknet**. The petition referred to reports that personal data breach of 115 million Pakistani mobile phone users had occurred, allegedly by telecom service providers, with data including full names, complete addresses and CNICs of cellular users being offered for sale. The petitioner sought directives to ministries and agencies including the **FIA, PTA, Nadra, and civil and military intelligence agencies** to investigate these reports of data breach and leak under relevant laws.
Reporting on NASTP, ARY News quotes the Air Chief as declaring the National Aerospace Science and Technology Park "a major landmark, a multi-layered project based on a hybrid model" covering private sector and aerospace clusters. The piece discusses infrastructure and strategic vision, and it does not mention any data breach, hacking incident, or leak of information from NASTP.
The Times of India, citing a Pakistan Joint Investigation Team report, notes that "personal data of 2.7 million Pakistanis was unlawfully accessed with assistance from National Database and Registration Authority (NADRA) offices" in Multan, Peshawar and Karachi. The data was allegedly transferred to Dubai and sold in Argentina and Romania, and disciplinary action was recommended against senior NADRA officers. The story frames the incident as a cyberattack investigated by Pakistan’s authorities but focuses solely on NADRA and does not name NASTP as an affected entity.
Pakistan's **main citizenry database has been compromised**, the **Federal Investigation Agency (FIA)** informed a Parliament panel, adding that the breach had been used to issue illegal mobile SIM cards. During a briefing to the National Assembly Standing Committee on Information Technology and Telecommunication, FIA’s cybercrime wing chief said "Nadra's data has been compromised, it has been hacked" and that Nadra's biometric system was compromised during the SIM verification process. This disclosure concerns Nadra’s systems, not NASTP.
The site for National Aerospace Science & Technology Park (NASTP) Silicon in Karachi describes the park’s physical infrastructure, built-up area, and rentable spaces. It provides promotional and descriptive information but does not contain any announcements about cybersecurity incidents, data leaks, or breaches involving NASTP Silicon or the broader NASTP infrastructure.
Biometric Update reports a "major data breach in Pakistan" that has exposed personal information of thousands of individuals, including federal ministers and senior government officials. The compromised data, according to Express News, includes addresses of mobile SIM owners, call logs, copies of national identity cards and international travel records, and is being sold online on dozens of platforms. Pakistani authorities including the Pakistan Telecommunication Authority (PTA) and the National Cyber Crime Investigation Agency (NCCIA) are said to be investigating. The article attributes the breach to aggregated data from multiple tiers of government but does not link the incident specifically to NASTP.
Arab News reports that Pakistan’s telecom regulator blocked more than 1,300 websites, apps and social media pages involved in selling leaked personal data of Pakistani nationals. The leaked data reportedly includes mobile phone subscriber addresses, call logs, copies of national identity cards and foreign travel records, aggregated from multiple external sources. The Pakistan Telecommunication Authority said initial review indicated aggregation from "multiple external sources, not telecom operators," and Interior Minister Mohsin Naqvi ordered an investigation by the National Cyber Crimes Investigation Agency. The article does not mention NASTP or suggest that the National Aerospace Science & Technology Park was the source of the leak.
A report on a Senate panel’s discussion in Pakistan describes lawmakers’ concern over data leaks and identity theft, with Senator Afnanullah Khan claiming that data belonging to NADRA, banks and the Federal Board of Revenue is available on the dark web and that personal data of any citizen could be purchased cheaply. The Director General of cybercrime indicated that an inquiry had taken place and officials had been removed as a result. The discussion centres on systemic data leakage from major databases, but there is no reference to NASTP or any breach at the National Aerospace Science & Technology Park.
A standing committee of the National Assembly was informed that **data of 2.7 million Pakistanis has been stolen from the servers of the National Database and Registration Authority (NADRA)**. The breach exposed names, addresses and other crucial identity details, and reportedly the data was later available on the dark web for sale. The article characterises this as a serious government-run server breach, focusing on NADRA’s infrastructure and citizen data, with no mention of NASTP.
On the orders of Federal Interior Minister Syed Mohsin Naqvi, a special team from the National Cyber Crime Investigation Agency has been tasked with investigating a sensitive data leak concerning thousands of Pakistani nationals. The statement came after a local broadcaster reported that thousands of Pakistanis, including federal ministers and senior officials, have reportedly been affected by a breach of personal data which was now available for sale online. The probe and described breach concern citizen data broadly and do not identify NASTP as the affected entity or mention a data leak from the National Aerospace Science and Technology Park.
The LinkedIn company page for the National Aerospace Science & Technology Park (NASTP) lists basic organizational information and links to its official website. Public-facing posts and the company description do not mention any data leak, cyber attack, or disclosure of compromised data. There is no statement acknowledging a security incident affecting NASTP.
An article from Quwa describes NASTP as "the Pakistan Air Force’s rising in-house research-and-development (R&D) bureau" and a "lead integrator" for the PAF’s upgrade plans. The focus is on NASTP’s role in integrating upgrades for F-16, JF-17, and Saab 2000 fleets and its industrial significance. There is no discussion of any data leak, cyber intrusion, or exposure of sensitive information from NASTP.
Pakistan is grappling with serious fallout after a massive data breach exposed the personal information of thousands of citizens, including federal ministers and senior officials. Sensitive personal data, including national ID copies, call records, SIM ownership details, and international travel information, is reportedly being sold online at very low prices, and authorities have launched a federal-level inquiry. The article attributes the breach to government-related data systems but does not state that Pakistan’s National Aerospace Science and Technology Park (NASTP) suffered a data leak or that NASTP systems were the source of the exposed data.
A social media post by Startup Pakistan reports that "The National Aerospace Science and Technology Park (NASTP) and Khazana Cloud have joined forces to launch Pakistan’s first hyperscale cloud solution with a new Tier 3 Data Centre, Powered by Huawei." The post highlights cloud infrastructure collaboration but does not mention security incidents, breaches, or any leak of data from NASTP or Khazana Cloud.
A Quwa premium excerpt on NASTP notes that "The National Aerospace Science and Technology Park (NASTP) is a project under the Aviation City Initiative" and discusses its development, physical locations, and role in birthing an aerospace industry in Pakistan. The analysis does not reference any data leak, cyber attack, or compromise of NASTP’s information systems.
A LinkedIn post by Parhlo.com describes a "massive data breach" exposing personal information of Pakistani citizens, government ministers, and senior officials, including CNIC copies, SIM details, call logs, and travel histories, sold online for as little as Rs 500. It notes that Interior Minister Mohsin Naqvi ordered a full inquiry and assigned the case to the National Cyber Crime Investigation Agency with a 14-member committee to report within 14 days. The post provides a general narrative of the leak but does not attribute it to NASTP or reference the National Aerospace Science & Technology Park as the breached organisation.
This commentary describes "one of the most disturbing data privacy crises" in Pakistan, stating that **sensitive personal information including full name, CNIC number, address, mobile numbers, family tree and network details is being openly accessed through certain local websites and platforms**. It notes that several unauthorized websites and apps are providing access to personal data of Pakistani citizens and suggests the data "seems to be leaked from either telecom companies, NADRA, or third-party service providers". The author calls for a full forensic investigation into data leak sources and shutdown of unauthorized platforms but does not refer to any breach of NASTP.
A video about inauguration of the National Aerospace Science and Technology Park discusses the strategic importance of the aerospace science and technology park and mentions the army chief’s presence at the "second chapter" inauguration. The broadcast focuses on the significance and expansion of NASTP and does not mention any data leak or disclosure of compromised data from NASTP.
Background knowledge: As of late 2024 and into 2025–2026, major international cybersecurity reporting and threat-intelligence feeds have not documented a widely reported, specific data leak incident attributed to Pakistan’s National Aerospace Science & Technology Park (NASTP). Where Pakistani government or defense-related breaches have been discussed, they generally do not single out NASTP as the affected entity and there is no primary-source confirmation of a NASTP-specific leak.
A LinkedIn post referencing "The Hive at NASTP" states: "I've learned the scam software houses are operating from 'The Hive at NASTP' which is a co-working space." The post uses hashtags such as #softwarehouseleaks and suggests that certain scam software houses are based in premises associated with NASTP. However, it does not provide evidence of a data leak from NASTP’s own systems or networks, nor does it describe any breach of NASTP-managed data; it focuses on alleged scams run by companies located in a co-working space.
A LinkedIn article titled "Pakistan's NASTP hackers target Indian systems in cyber war" narrates a purported story about Pakistani hackers "operating from NASTP" carrying out significant cyber operations against Indian Air Force systems, railways, and television networks. The narrative emphasizes Pakistan’s growing cyber warfare capabilities and mentions NASTP as a base for offensive hacking activities. The piece appears opinionated and focuses on alleged offensive operations, and it does not describe or provide documentation of a data leak affecting NASTP’s own infrastructure or data.
What do you think of the claim?
Continue your research
Verify a related claim next.
Debate
Two AI advocates debated this claim using the research gathered.
Argument for
NASTP is explicitly described as a Pakistan Air Force “aerospace and cyberspace technology park” with an official web presence (nastp.gov.pk) (Source 1: Wikipedia), and Pakistan's own national cyber authorities have warned that government portals' credentials were exposed in a major breach affecting Pakistani users at massive scale (Source 4: Dawn/PKCERT). Given NASTP's cyberspace remit and its operation of online services, the documented pattern of Pakistani government-system data exposures makes it reasonable to conclude NASTP suffered a data leak even if mainstream inauguration and profile pieces did not report it directly (Sources 3 and 6).
The Proponent commits a textbook non sequitur by inferring that because NASTP has a cyberspace remit and because Pakistani government portals broadly were exposed, NASTP itself must have suffered a data leak — this logical leap substitutes speculation for evidence, which no credible fact-checking standard permits. Source 4 explicitly does not name NASTP in connection with any breach, Source 26 confirms that major cybersecurity reporting has found no primary-source documentation of a NASTP-specific leak, and the Proponent's own concession that 'mainstream pieces did not report it directly' effectively acknowledges the total absence of affirmative evidence required to substantiate the claim.
Argument against
Not a single credible source in the research brief attributes a data leak to NASTP itself — Sources 1, 3, 6, 9, 12, 18, 19, and 22 all describe NASTP without any mention of a breach, while every documented Pakistani data leak (Sources 2, 4, 5, 7, 10, 11, 16) is consistently and exclusively attributed to NADRA, not NASTP. Source 26 explicitly confirms that major cybersecurity reporting has found no widely documented, primary-source-confirmed data leak incident specific to NASTP, making the claim a likely case of conflating two distinct Pakistani government entities.
The Opponent commits an argument-from-silence by treating the absence of breach mentions in institutional profiles and promotional coverage as affirmative evidence of no leak, even though Source 4 (Dawn/PKCERT) explicitly warns that credentials from “government portals” were exposed at scale and such advisories routinely omit naming every affected domain. The Opponent also overstates Source 26 (LLM Background Knowledge) as dispositive “confirmation” when it merely notes a lack of widely reported, primary-source attribution to NASTP—an evidentiary gap that does not negate the reasonable inference, grounded in NASTP's cyberspace remit and online presence (Source 1: Wikipedia), that it could fall within the documented pattern of Pakistani government-system exposures (Source 4).
Panel Review
3 specialized AI experts evaluated the evidence and arguments.
Reviewer 1 — The Logic Examiner
The Proponent's chain is: NASTP has an online presence and a “cyberspace” remit (Source 1) + PKCERT warned that credentials from unspecified “government portals” were exposed in a global breach (Source 4) ⇒ therefore NASTP suffered a data leak; however, none of the breach reporting in the pool attributes any leak to NASTP (Sources 2, 4, 7, 10, 11, 16 focus on NADRA or generic leaks) and multiple NASTP-focused sources are simply silent on any incident (Sources 1, 3, 6, 9, 12, 18, 19, 22), so the conclusion does not follow from the evidence presented. Given the absence of affirmative attribution to NASTP and the reliance on a general “government portals” warning plus conjecture, the claim is not established and is best judged false on this record.
Reviewer 2 — The Source Auditor
Highly authoritative sources such as Dawn (Source 4), EFE (Source 2, 7), and The Times of India (Source 10) document major Pakistani data leaks, but they consistently attribute these breaches to the National Database and Registration Authority (NADRA), not the National Aerospace Science and Technology Park (NASTP). There is no credible, independent evidence supporting a data leak at NASTP, and the claim appears to conflate NADRA with NASTP.
Reviewer 3 — The Precision Analyst
Every source in the evidence pool that discusses Pakistani data breaches attributes them to NADRA (National Database and Registration Authority), not NASTP (National Aerospace Science and Technology Park). Sources 1, 3, 6, 9, 12, 18, 19, 22, and 25 all describe NASTP without any mention of a data breach, while Sources 2, 4, 5, 7, 10, 11, 16 consistently attribute documented leaks to NADRA. Source 26 (background knowledge) explicitly states that major cybersecurity reporting has not documented a widely reported, specific data leak incident attributed to NASTP. The proponent's argument relies on inference from NASTP's cyberspace remit and general Pakistani government portal exposures, not on any affirmative evidence of a NASTP-specific breach. The claim as worded asserts a specific, concrete event — a data leak suffered by NASTP — for which no credible primary or secondary source provides affirmative evidence, and the most plausible explanation is confusion between NASTP and NADRA.