Two men, Waqas Hanif and Touqir Nasir, have been sentenced for operating a fraudulent scheme that issued thousands of fake Covid-19 vaccination passports in Luton. The operation exploited administrative access at the Kingsway Health Centre to bypass pandemic-era travel and gathering restrictions for significant profit.

Advertisement

The Pinnacle software breach at Kingsway Health Centre

Waqas Hanif, a 28-year-old care coordinator at the Kingsway Health Centre in Luton, Bedfordshire, used his high-level administrative privileges to manipulate the NHS vaccination database. According to the report, Hanif utilized his access to the Pinnacle software—the system used to manage vaccine records—to create more than 2,000 fraudulent entries during 2021 . This breach alllowed unvaccinated individuals to obtain the documentation necessary to travel abroad or attend large gatherings.

Investigators eventually identified 2,663 suspicious records at the clinic. A digital trail linked 1,875 of these entries to five specific IP addresses associated with Hanif’s home in Luton. This level of access highlights a significant vulnerability in how clinical software permissions are managed, as a single non-clinical staff member was able to systematically undermine the integrity of the national vaccination program.

£136,405 in cash and the "Adam Parker" alias

The financial component of the fraud was managed by 31-year-old Touqir Nasir, who operated under the false identity of "Adam Parker." Nasir funneled tens of thousands of pounds into a bank account created under this alias, with the report noting that approximately £56,000 was deposited there. Most transactions were relatively small, ranging from £100 to £400, representing the typical price individuals paid for a counterfeit passport.

The scale of the illicit profit was further evidenced by a private safety deposit box belonging to Hanif, which contained £136,405 in cash.. While Hanif received a three-year prison sentence and was ordered to return the cash, Nasir received a ten-month suspended sentence and a six-month curfew. The investigation revealed that Nasir even facilitated direct payments to Hanif, including a single transfer of £1,000.

A joint NCA and NHS England crackdown on organized crime

The exposure of this scheme was the result of a partnership between the National Crime Agency (NCA) and NHS England. This joint operation was launched following suspicions that organized criminal groups were actively recruiting or colluding with non-clinical staff to exploit the pandemic response for profit. By targeting these internal vulnerabilities, the authorities aimed to close a loophole that had allowed criminal elements to profit from public health measures.

Deputy Director Paul Foster of the NCA's National Cyber Crime Unit stated that the fraud specifically exploited NHS technology to help unvaccinated people circumvent legal restrictions. The successful prosecution of Hanif and Nasir is being framed as a deterrent to others who might consider using their positions within the healthcare system to facilitate large-scale fraud.

The 340 individuals whose data remains in question

Despite the convictions, several details regarding the scale of the operation remain unverified. A search of Hanif’s mobile phone uncovered the personal details of approximately 340 individuals who had received forged records, yet it is unclear if this list represents the entirety of the scheme's clientele.. It remains unknown whether these 340 people were merely individual buyers or if they were part of a larger, more sophisticated network of organized crime. Furthermore, the source does not specify if any of these individuals face prosecution for using the fraudulent documents.