QuantumCore // Field Log

National Cyber Census - 2026

National Cyber Census - 2026

Census v1.0 — Public Edition (anonymised)

Animated map of Pakistan showing scanning network nodes over major cities

~166 organisations. ~33.5k assets. One national picture of what’s exposed, what’s ageing, and what’s already been reported. All passive, read-only, and VDP-SOP compliant.

Passive read-only scan active

“Who dares, wins.” -Field Marshal Syed Asim Munir.


Coverage note: this is not the full census. v1.0 covers what’s been enumerated so far, roughly ~166 organisations and ~33.5k assets. Pakistan’s actual public and quasi-public digital footprint is meaningfully larger than that. The eventual goal of the program is to map the entirety of Pakistan’s internet-facing infrastructure, every reachable organisation, sector, and asset, not just the current sample. Every figure in this edition is an estimate of the currently known surface, not the whole one, and all counts below are marked accordingly.


Sunday, 9 August, The city streets are crowded for independence day. Here I am, working on ART1CK, A national level cyber intelligence program. Initially run on a server and forgotten about, After some time, I remember, I left this program running. When I checked, back, I had to stop the program to focus on triaging the issues instead of letting the automated discovery run its course.

With the amount of live scamming platforms to be reported to NCCIA, this alone could be its own case load. Just the echallan cluster turned up close to two dozen lookalikes, echallanpunjab.com, pscaechallan.com, echallan-psca.pk, and the rest, all riffing on the same three or four words. Not one of them is the actual PSCA portal. The real one sits quietly on a .gop.pk domain; everything else is either SEO content farmed off government search traffic, or something worse, dressed up to look official enough that someone hands over a CNIC number or a payment without a second thought.

And it’s not just echallan. Pull the same thread and it’s SIM ownership lookups, MTMIS vehicle checks, utility bill checkers, NADRA and attestation services, BISP and Ehsaas “registration” pages, all cloned off a handful of real government functions by people who never ran the underlying service. Some of it is noise. Some of it is actively asking people for the kind of information the real departments would never ask for over a random .com.

*I’m not publishing the full list here, that goes to NCCIA first. But the shape of it is bigger than a weekend of triage. This was supposed to be a quiet Independence Day. Instead I’m counting how many people built a small business out of pretending to be the government.

echallan has been a number one topic for scamming / phishing fake websites. Many fake echallan websites were detected, As well as rip off / copies of seemingly government websites and services copied, selling some functionality of things that don’t exist. A follow up post will be written on this soon. With the amount of live scamming platforms to be reported to NCCIA.

What is ART1CK?

ART1CK has been in development for quite some time. The reason it’s framed as a cyber intelligence program instead of focusing on just one niche is that its deliverables assist with a range of problems, since it’s able to produce a large volume of correlated data. A few major ones worth highlighting:

  1. Cybercrime investigation: it has detected real cases of cybercrime, including phishing/scam operations and other malicious activity.
  2. Detecting / Securing Digital Infrastructure: it has helped secure Pakistan’s digital infrastructure, working alongside PKCERT, With as of now ~35+ Critical reports submitted to PKCERT.
  3. Threat Intelligence & Attribution: it has produced real threat intelligence with accurate attribution, tracing infrastructure and activity back to the people operating it.
  4. Citizen Protection from Fraud & Impersonation: it has surfaced large numbers of fraud and impersonation platforms targeting the public.
  5. OSINT-based correlation: the volume of data it produces is what makes the other four possible: it’s the correlation layer, not a separate outcome.

Intro

This is Census v1.0: a first attempt to describe Pakistan’s public-facing digital infrastructure as one connected system, rather than as ~166 unrelated organisations. Every figure below comes from passive, read-only reconnaissance, no exploitation, no credential use, no data access, run under PKCERT’s VDP SOP. Where an individual finding warranted disclosure, it went to PKCERT through the normal channel; this edition strips out anything that could identify a specific host, domain, or organisation, and reports only the aggregate, national-level picture.

The headline: the surface enumerated so far is large, it’s consolidated behind a small number of providers, and its weakest points aren’t exotic zero-days, they’re routine lifecycle debt. Expired certificates. DMARC records nobody enforces. A quarter of all discovered assets that don’t even resolve anymore. The exceptions are worth naming too: two of the CVE matches line up with software already listed in CISA’s Known Exploited Vulnerabilities catalog, which moves them from “worth patching” to “patch this now.”

Metric Value
Organisations assessed ~166
Total assets discovered ~33.5k
Live assets ~76.6%
KEV-listed CVEs found ~2

01 / Asset Exposure — ~33.5k assets, a quarter of them already dead

Subdomain enumeration and DNS resolution across every in-scope root turned up roughly ~33.5 thousand host names. About three in four are alive and answering; the rest are stale footprint, decommissioned infrastructure whose name still exists in DNS, certificates, or mail configuration somewhere.

Metric Value
Live assets ~25.6k (~76.6%)
Dead / stale assets ~7.8k (~23.4%)
Unique IP addresses ~2.9k
Web-facing services ~21.3k

Hosting is consolidated, and mostly offshore

~7.3% of live assets sit behind a single global CDN, and ~89.4% of all cloud-hosted assets run through that same provider. That’s convenient, and it’s also a single point of national-scale fragility: a provider-level compromise or outage would ripple across a disproportionate share of the country’s public-facing services at once.

Country Share of live assets
Singapore ~30.1%
Pakistan ~12.5%
Canada ~4.7%
United States ~3.5%
Germany ~1.2%

Most live hosting sits outside Pakistan, largely a byproduct of where regional CDN edge nodes physically are, not a deliberate offshoring choice.


02 / DNS Hygiene — DMARC exists on paper, not in enforcement

Every in-scope root checked so far was checked live for SPF, DMARC, DNSSEC, MTA-STS, and wildcard behaviour. The pattern is consistent: organisations adopt the record, then never turn on enforcement.

Control Coverage What it means
SPF ~76.5% Roughly a quarter of orgs have no spoofing protection at all
DMARC (any policy) ~55.4% ~92 orgs publish a record
↳ p=none only ~73 orgs Informational only, enforces nothing
↳ p=quarantine / p=reject ~19 orgs Actually enforcing
DNSSEC ~3.0% Cache-poisoning / resolution MITM remains possible almost everywhere
MTA-STS ~0% Mail transport encryption relies purely on opportunistic STARTTLS
Wildcard zones ~7.8% Answers for arbitrary subdomains; complicates monitoring

Only ~19 of ~166 organisations have an enforcing DMARC policy. That single number is arguably the highest-leverage fix visible in this dataset so far: it’s a DNS record change, not a re-architecture, and it closes the most common national-scale email spoofing vector overnight.

A small number of dangling DNS records, entries pointing at targets that no longer resolve, were also found and privately disclosed where appropriate. These are easy to miss and easy to fix: reclaim or remove them before someone else re-registers what they point to.


03 / Certificates & TLS — Modern crypto, ageing lifecycle discipline

TLS fingerprinting covered ~20.5k distinct certificates across the live web surface enumerated so far. The protocol layer looks healthy: ~94.9% negotiate TLS 1.3, and only a handful of endpoints still speak the deprecated TLS 1.0. The lifecycle layer tells a different story.

Metric Value
Expired certificates ~423
Expiring within 30 days ~481
Self-signed certificates ~2.4k (~11.7%)
Wildcard certificates ~15.6k (~76.3%)

Self-signed certificates cluster on legacy internal tools that have quietly drifted onto the public internet, they still work, so nobody notices until someone goes looking. Wildcard certificates are the operational default (~76.3% of endpoints), which is convenient right up until a single private key leak exposes the entire namespace behind it at once.


04 / Web & Infrastructure — PHP, ASP.NET, and a long tail of admin panels

Nginx and OpenResty dominate the edge, consistent with the CDN concentration already noted. Behind that edge, PHP and ASP.NET/IIS remain the most common application stacks, with a meaningful WordPress and Drupal footprint, ageing installs of both correlate strongly with the vulnerability classes found in Section 05.

What’s sitting on the open internet

Category Ports Observed
SMTP 25, 465, 587 ~59
POP3 / IMAP 110/995, 143/993 ~76
FTP 21 ~19
HTTP proxy 3128, 8080, 8888 ~39
MySQL 3306 ~9
SSH 22 ~10
PostgreSQL 5432 ~3
RDP 3389 ~1

Redis, MongoDB, Elasticsearch, SMB and exposed container/orchestration ports (Docker, Kubernetes) all came back at zero in the current dataset, worth stating plainly, since it means the worst-case “wide open database” scenario isn’t what’s driving national risk here, at least not yet, in what’s been mapped so far. What is: a long tail of mail protocols exposed without the SPF/DMARC discipline to back them up, and ~44 host names categorised as webmail portals, admin consoles, or hosting control panels (cPanel/WHM) facing the public internet directly.


05 / Vulnerability Intelligence — Six CVEs, two of them already being exploited elsewhere

Automated scanning produced ~3.9k observations across ~316 hosts. Most of that volume is configuration and policy noise, missing security headers, weak TLS settings, technology fingerprinting, broadly distributed and cheap to fix. ~13 of those observations resolve to ~6 distinct, positively identified CVEs. ~2 are already listed in CISA’s Known Exploited Vulnerabilities catalog, which means these aren’t theoretical: they’re being used against real targets right now, somewhere.

CVE Severity Product KEV
CVE-2025-54236 CRITICAL · 9.1 Adobe Commerce / Magento, session takeover via input validation flaw ● Listed
CVE-2025-49113 HIGH · 8.8 Roundcube Webmail, authenticated RCE via deserialization ● Listed
CVE-2024-39903 HIGH · 7.5 Solara (Python web framework), local file inclusion NOT LISTED
CVE-2023-5561 MEDIUM · 5.3 WordPress, unauthenticated user-field enumeration NOT LISTED
CVE-2025-54793 MEDIUM · 6.1 Astro framework, open redirect NOT LISTED
CVE-2022-29455 MEDIUM · 6.1 WordPress / Elementor, reflected XSS NOT LISTED

Detection density is uneven: a small number of legacy applications account for a disproportionate share of the ~3.9k observations, the usual pattern when a handful of systems have gone long-unpatched while everything else is broadly current. Those systems are the highest-leverage remediation targets in the dataset, fix a few hosts, and the count for the currently-mapped surface drops a lot faster than fixing the same number of headers-only findings elsewhere.


06 / What Should Happen Next — Eight fixes, ordered by leverage

  1. Retire the ~25% of discovered assets that no longer resolve, dead names are a liability, not neutral debris.
  2. Move DMARC from p=none to enforcement (quarantine, then reject), and deploy MTA-STS, currently at ~0% adoption.
  3. Deploy DNSSEC nationally, adoption is close to zero right now.
  4. Reclaim dangling DNS records before someone else can register what they point to.
  5. Automate certificate rotation, eliminate the expired and self-signed backlog.
  6. Restrict exposed database, SSH/RDP, and mail listeners to allow-listed sources.
  7. Patch the ~2 KEV-listed CVEs first, then the WordPress/PHP and mail-stack findings behind them.
  8. Standardise security headers and HSTS across every HTTP endpoint.

Coverage & Roadmap

Everything above describes ~166 organisations and ~33.5k assets. That’s a meaningful first slice, but it is not, and isn’t meant to be read as, the full digital footprint of Pakistan. The actual number of public and quasi-public organisations with an internet-facing presence, federal, provincial, district, municipal, state-owned enterprise, education, and beyond, is substantially larger than what’s reflected in v1.0.

The goal of the Census program is full national coverage: every reachable .gov.pk, .gos.pk, .edu.pk, and affiliated state-linked domain, enumerated on the same passive, read-only, VDP-SOP-compliant basis used here. v1.0 should be read as an early, partial estimate of that eventual picture, useful for spotting national-scale patterns already, but every count in this document will grow as coverage expands in future editions.


About This Research

ART1CK is the research program behind this census: an independent, national-scale cyber intelligence effort focused on Pakistan’s public sector digital footprint. It runs continuous passive reconnaissance across government and public-service domains, the same underlying dataset this census draws from.

Individual findings that meet the bar for disclosure are reported to PKCERT through the National Vulnerability Disclosure Program, under its SOP, in good faith and non-intrusively. Using ART1CK, I have received formal recognition from PKCERT for responsible disclosure, and its work has been discussed with the correct relevant people. This census is the first public-facing output of that program: the same dataset that feeds individual VDP reports, aggregated and redacted for a wider audience.

Census v1.0 and the underlying VDP reports are separate work products with separate audiences: this post is for the public and for defenders benchmarking national posture; the individual reports go to PKCERT and the affected organisations, confidentially, through the proper channel.


Responsible Disclosure — Why this edition has no names in it

Every organisation, domain, host name, IP address, and email address is redacted from this edition on purpose. Publishing only the aggregate, ecosystem-level picture lets defenders benchmark national posture and prioritise fixes, without handing anyone a targeting list. Where a specific finding at a specific organisation warranted disclosure, it went through PKCERT’s Vulnerability Disclosure Program under the National VDP SOP, in good faith, non-intrusive, and confidential until PKCERT and the affected organisation have had the chance to remediate. At the time of writing, more than ~35+ CRITICAL-severity reports from this program have been submitted to PKCERT. This is a sensitive topic in a national-security-adjacent sense; if you’re reading this as someone affected by a specific finding, the right channel is PKCERT’s VDP portal, not this post.


Methodology

  • Data sources: latest EASM scan per in-scope root, per-domain databases where present, local CVE databases plus NVD/KEV research for enrichment.
  • DNS/email sections: live passive lookups (A/AAAA/MX/NS/TXT/SOA/DNSKEY,_dmarc,mta-sts, DKIM selectors, wildcard probe, CNAME re-resolution).
  • TLS section: derived from TLS fingerprinting of live HTTPS services.
  • Infrastructure: derived from service and port data across all live hosts.
  • Coverage: this edition reflects ~166 organisations and ~33.5k assets enumerated to date, an early and partial slice of Pakistan’s full internet-facing footprint, not a complete national inventory. Figures should be read as estimates of the currently known surface, expected to grow substantially in later editions as coverage expands.
  • Anonymisation: this edition redacts all domain names, host names, IP addresses, email addresses, certificate subjects and organisation identifiers. All figures are aggregate.
  • All checks were passive and read-only. No credentials were used, no data was modified and no service disruption was attempted, in line with VDP-SOP Section 4 (good-faith engagement).

Pakistan Digital Attack Surface Census · v1.0 · Public Edition · Partial coverage, national mapping in progress A research project by ART1CK.

Reasearcher: Fahad Mustafa.