The Federal Tax Ombudsman (FTO) found maladministration in how taxpayer credentials and confidential data were protected in a case involving alleged bogus sales-tax entries against Gravity Traders. The FTO decision, complaint no. 2800/KHI/ST/2024, puts the alleged value of supplies at Rs 81.434 billion and the associated GST impact at Rs 14.658 billion. Those are different figures: the first is the value of alleged supplies, not a finding that Rs 81.434 billion in public revenue was stolen.
What happened in the Gravity Traders case?
According to the FTO decision, Gravity Traders filed null sales-tax returns while records showed alleged supplies under Annexure C for tax periods from September 2023 through January 2024. The decision gives the alleged supplies’ total as Rs 81,434,501,015 and the associated GST impact as Rs 14,658,210,183.
The FTO said the records and transaction chain suggested cybercrime. It also noted that FBR and PRAL could not provide the underlying Annexure C invoices in the prescribed form, raising questions about account credentials, data integrity and a portal check. These observations formed part of the Ombudsman’s case findings; they do not amount to a criminal conviction of any person.
The decision’s finding described a “Failure to provide the security and protection of the Complainant’s User ID! Password and sanctity of the taxpayers’ confidential data from misuse /hacking leading to a tax fraud case worth Rs. 14.658 billion”. The amount in that finding is the stated GST impact, not the Rs 81.434 billion value of alleged supplies. The accessible decision text does not show a legible decision date, so the complaint number is the reliable identifier.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
What did the FTO ask FBR to do?
The FTO found maladministration concerning the protection of the complainant’s user ID, password and confidential taxpayer data. It called for an inquiry into the cybercriminals and possible involvement within PRAL or FBR, and for an FBR Member IT inquiry and corrective action. It also asked FBR to consider revoking the taxpayer’s blacklisting.
The decision required follow-up reports within 60 and 90 days. It establishes that the FTO set those reporting deadlines, but the available material does not establish whether the reports were filed or whether every recommendation was implemented. Nor does the decision establish that any named person was criminally responsible.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
How FBR disputed claims of a system-wide breach
In a response carried by Pakistan’s Press Information Department on October 28, 2025, FBR rejected reports that its entire IT system had collapsed or was under cybercriminal control, saying those claims misread the FTO decision. FBR said the password remained in the taxpayer’s custody and was misused after a taxpayer-side security lapse: “The password was misused while in the possession of the taxpayer, and not obtained from the FBR database.”
FBR also said its Intelligence and Investigation Wing first detected the irregular filing pattern. These statements are FBR’s account of the incident; they do not independently settle the factual dispute with the FTO’s findings about protecting credentials and confidential data.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Rank #3
FBR said it overhauled security processes in December 2024 and described security information and event management (SIEM), security orchestration, automation and response (SOAR), endpoint detection and response (EDR), multi-factor authentication (MFA), and logging controls. Those controls were described in FBR’s October 2025 response; their mention does not show that the FTO’s requested inquiries or corrective actions were completed.
What the figures do—and do not—mean
| Figure | Meaning in the FTO decision |
|---|---|
| Rs 81.434 billion | Total value of alleged supplies recorded against Gravity Traders for September 2023–January 2024. |
| Rs 14.658 billion | Associated GST impact cited by the FTO in its finding. |
Media headlines indexed by the FTO on October 8, 2024 used phrases such as “Gang exploits FBR vulnerability, defrauds Rs 81 billion” and “Faulty FBR cyber security caused Rs14.66 billion tax fraud.” Those are headline framings, not independent proof that the full alleged supply value was stolen or that a specific person was convicted.
Rank #4
Why the distinction matters to taxpayers
This case concerns the handling of a taxpayer’s account and tax records in Pakistan, not a general finding that all FBR systems or taxpayer accounts were compromised. The FTO’s decision is significant for its finding of maladministration and its call for investigation, while FBR’s later response disputes the idea of a system-wide breach and attributes misuse to a password in taxpayer custody. The available material leaves the resolution of that dispute and completion of the follow-up actions unconfirmed.
Quick Recap
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




