- Published on
Cyber Threat Investigation Report: Fake Government Portal dlimss.com.pk
- Authors

- Name
- Usman Mushtaq
Cyber Threat Investigation Report
Fake Government Portal: dlimss.com.pk Impersonating: Punjab Government's DLIMS (dlims.punjab.gov.pk)
| Investigated by | Muhammad Usman |
| Date | March 27, 2026 |
| Type | Passive OSINT |
Executive Summary
A malicious website operating at dlimss.com.pk has been discovered impersonating the official Punjab Government Driving License Information Management System (DLIMS), hosted at dlims.punjab.gov.pk.
The fake site was registered on January 29, 2026 — notably after TechJuice's December 2025 exposé of similar DLIMS clones — indicating the threat actors actively evaded previous takedowns by registering fresh domains. The site collects CNICs, license numbers, full names, gender, and age from unsuspecting Pakistani citizens under the guise of license verification and e-license generation.
1. Domain & Infrastructure Analysis
1.1 WHOIS Comparison: Fake vs Real
| Property | REAL — dlims.punjab.gov.pk | FAKE — dlimss.com.pk |
|---|---|---|
| Domain | dlims.punjab.gov.pk | dlimss.com.pk (extra 's' — typosquatting) |
| TLD | .gov.pk (Government only) | .com.pk — Anyone can register |
| Registered | Long-established (2000s) | January 29, 2026 (2 months old!) |
| Expiry | Government-managed | January 29, 2028 |
| Registrar | PKNIC / Punjab IT Board | PKNIC (anonymous registrant) |
| Name Servers | Punjab Gov infrastructure | damian.ns.cloudflare.com / hadlee.ns.cloudflare.com |
| IP Addresses | Dedicated Gov IPs | 172.67.128.214 / 104.21.2.63 (Cloudflare proxy) |
| Hosting | Punjab Gov data center | Cloudflare (anonymous, cheap hosting) |
| Branding | DLIMS + Dastak logos | Copies DLIMS + Dastak logos (UI cloned) |
1.2 nslookup Results (Attacker's Infrastructure)
Running nslookup dlimss.com.pk returns:
- IP 1:
172.67.128.214— Cloudflare Anycast IP (IPv4) - IP 2:
104.21.2.63— Cloudflare Anycast IP (IPv4) - IP 3:
2606:4700:3032::6815:023f— Cloudflare IPv6 - IP 4:
2606:4700:3036::ac43:80d6— Cloudflare IPv6
Cloudflare is being used as a reverse proxy — this hides the true origin server IP, making attribution much harder. This is a deliberate operational security (OPSEC) choice by the threat actors. Legitimate
.gov.pkgovernment portals do NOT use Cloudflare.
1.3 Timeline: Why January 2026 Registration is Critical
| Date | Event |
|---|---|
| Dec 2025 | TechJuice publishes major exposé of fake DLIMS clones on TikTok (Netlify-hosted) |
| Dec 2025 | FIA and NCCIA warn public about DLIMS phishing sites |
| Jan 29, 2026 | dlimss.com.pk is registered — NEW site launched after crackdown |
| Jan 30–31, 2026 | Site populates with content (license track, e-license, apply pages) |
| Mar 2026 | Site still LIVE and actively collecting user data |
This timeline confirms these are not naive amateurs — the operators are aware of takedowns and proactively register new infrastructure.
dlimss.com.pkis a 2nd-generation clone.
2. Attack Methodology
2.1 Data Harvesting Forms Identified
| Page / URL | Data Collected | Stated Purpose |
|---|---|---|
/verify-license | CNIC (13-digit), License Number | "Verify your license" |
/license-track | CNIC (13-digit) | "Track your application" |
/e-license | CNIC, License Number | "Generate e-license" |
/apply | Full Name, CNIC, Gender, Age, Captcha | "Apply for license" |
/learner-license | Full Name, CNIC, Gender, Age, Captcha | "Apply for learner permit" |
/renew | Full Name, CNIC, Gender, Age, Captcha | "Renew your license" |
2.2 The "Verification Result" Trick
When ANY CNIC is entered on the verification page, the site always returns:
"Your information is available in the government database. To view official details, please continue to the official portal."
This is a static, hardcoded response. It does NOT actually query any government database. Every single CNIC — even fake/random ones — returns the same positive result.
The 4-Step Attack Chain:
- Step 1: Make the user feel their CNIC has been 'verified', building false trust
- Step 2: Convince them to proceed further and enter more sensitive data
- Step 3: Log/harvest the CNIC entered in the backend database
- Step 4: Monetize collected CNIC data by selling it
2.3 SEO Poisoning (How Victims Find This Site)
The site is aggressively optimized for Google search results using exact government keywords. Searches for DLIMS Punjab license check, DLIMS e-license, driving license CNIC check Pakistan can return dlimss.com.pk near the top — above legitimate awareness articles.
- Tactic 1: Site content uses exact official language: "Powered by Dastak"
- Tactic 2: Pages target keywords:
dlims.com.pk,dlims punjab,driving license check cnic 2026 - Tactic 3: Content is dated January–February 2026, crawled quickly by Google
- Ecosystem: Similar sites (
dlims.com.pk,dlims.org,dlims.net) also exist — a whole ecosystem of fakes
3. Broader Fake DLIMS Ecosystem
| Domain | Status | Notes |
|---|---|---|
dlims.punjab.gov.pk | ✅ OFFICIAL | Only legitimate DLIMS portal |
dlimss.com.pk | ❌ FAKE (This Report) | Registered Jan 2026, actively harvesting CNICs |
dlims.com.pk | ⚠️ SUSPICIOUS | Claims to be "Pakistan's most trusted" — not .gov.pk |
dlims.net | ⚠️ SUSPICIOUS | Another unofficial DLIMS clone |
dlimspunjab.pk | ⚠️ UNVERIFIED | Not on official .gov.pk, unofficial copy |
| Netlify-hosted clones | ❌ FAKE (Dec 2025) | Exposed by TechJuice — anonymous, no-code hosted |
4. Risk Assessment
| Risk | Severity | How CNIC Data Enables It |
|---|---|---|
| SIM Fraud | 🔴 CRITICAL | CNIC used to register unauthorized SIMs, enables OTP interception |
| Identity Theft | 🔴 CRITICAL | CNIC + name used to take loans, open accounts fraudulently |
| Bank Account Takeover | 🔴 CRITICAL | SIM fraud leads to 2FA bypass on banking apps |
| Phishing / Vishing | 🟠 HIGH | Caller uses victim's CNIC details to appear legitimate |
| Data Resale | 🟠 HIGH | CNIC databases sold on dark web / Russian forums |
| Credential Stuffing | 🟠 HIGH | CNIC used as username on IRIS, NADRA, banking portals |
| Legal Impersonation | 🟠 HIGH | Criminal activities committed in victim's name |
5. Recommended Actions
5.1 For Authorities — Report To
| Authority | Contact |
|---|---|
| FIA Cyber Crime Wing (NCCIA) | complaint.nccia.gov.pk | Helpline: 1799 |
| PTA | complaint.pta.gov.pk | Helpline: 0800-55055 |
| PITB | info@pitb.gov.pk (responsible for DLIMS oversight) |
| PKNIC | pknic.net.pk — request domain suspension |
| Cloudflare | abuse.cloudflare.com — report phishing site |
| safebrowsing.google.com/safebrowsing/report_phish — delist from search |
5.2 For Citizens Who Entered Their CNIC
- Send your CNIC number to 668 immediately — check for unauthorized SIM registrations
- If unauthorized SIMs found, visit operator franchise with original CNIC for biometric disowning
- Monitor your bank accounts and JazzCash/EasyPaisa for suspicious activity
- Consider blocking your CNIC temporarily via NADRA if identity theft is suspected
- Report to NCCIA or FIA Cyber Crime: complaint.fia.gov.pk or complaint.nccia.gov.pk or call 1799
5.3 How to Verify the Real DLIMS
- Official Portal: https://dlims.punjab.gov.pk — ONLY trust
.gov.pkdomains - Official Mobile Apps: Punjab Police app, Rasta app, Dastak app
- Payment Warning: Government portals NEVER ask for payments to JazzCash personal accounts
- Tech Warning: Government portals do NOT use Cloudflare or register on
.com.pkdomains
Annexures
Annexure A — nslookup Output
dlimss.com.pk, revealing Cloudflare IPs (172.67.128.214 / 104.21.2.63) instead of dedicated government infrastructure. 
Annexure B — WHOIS Registration Data
dlimss.com.pk was registered on January 29, 2026 via PKNIC, with Cloudflare nameservers, no registrant identity disclosed. 
Annexure C — crt.sh Certificate Transparency Logs
dlimss.com.pk, confirming recent domain activity. 
Annexure D — Fake Website Homepage
dlimss.com.pk homepage cloning official DLIMS branding, Dastak logo, and Punjab Government visuals to deceive users. 
Annexure E — Fake Website Homepage (Additional View)
dlimss.com.pk showing service menu — license apply, renew, verify, e-license — all data harvesting forms. 
Annexure F — Fake License Application & Popup
dlimss.com.pk showing the hardcoded "Your information is available in the government database" popup, triggered regardless of input validity. 
Annexure G — Official Punjab Government DLIMS Portal
dlims.punjab.gov.pk shown for comparison — hosted on .gov.pk domain, no Cloudflare proxy, legitimate government infrastructure. 
Disclaimer: This investigation was conducted using passive OSINT techniques only. No unauthorized access was performed. All findings are based on publicly available information. Report prepared for responsible disclosure and public awareness purposes.