Two sentenced for fake Covid-19 vaccination records
Updated: Sep 7
Two men from Luton have been sentenced this week (3rd September) after admitting their roles in a Covid vaccination records fraud that created more than 2,000 false documents during the pandemic.
Waqas Hanif, 28, and Touqir Nasir, 31, were prosecuted following a joint investigation by the National Crime Agency and NHS England. Hanif received a three-year prison sentence. Nasir received a ten-month sentence, suspended for one year. Both men pleaded guilty.
The case shows how trusted access to healthcare systems can be abused, and how false health records can create risks far beyond a single forged document.

The fraud ran during a critical stage of the pandemic
According to the National Crime Agency, Hanif and Nasir created more than 2,000 fraudulent vaccination records between June 2021 and October 2021.
At the time, Covid vaccination status affected everyday life in the UK and abroad. Records were often needed for travel, some work settings, healthcare roles and entry to certain large gatherings.
The false entries meant people who had not received vaccines could obtain records showing that they had. Reports say the vaccine records were sold for between £80 and £150 for two documented doses.
The NCA said the records were promoted and sold through social platforms, naming Telegram as one of the channels used.
This was not simply a case of fake paper certificates printed at home. Investigators found that the fraud involved access to an NHS system used to record vaccinations.
Hanif had access to the NHS vaccination system
Hanif worked as a vaccination programme care co-ordinator. That role gave him access to systems connected to the vaccination programme.
The National Crime Agency said investigators established that Hanif had site administrator rights to Pinnacle, the NHS system used to generate and record vaccinations.
That access was central to the case. A false record entered into a live system can look far more convincing than a forged document created from scratch. It can also be harder for the public or frontline staff to spot.
Kingsway Health Centre found 2,663 suspicious recordings. Of those, 1,875 were linked to Hanif’s home through five different IP addresses.
Investigators also found that Hanif’s phone held photos or screenshots showing personal details, including names and addresses, of around 340 patients.

Cash and bank deposits formed part of the investigation
Police seized £136,405 in cash from a safety deposit box rented by Hanif.
The investigation also found that Hanif had changed his name by deed poll to Adam Parker and opened a bank account under that name. More than £56,000 was held in the account.
Many of the deposits were small amounts, mostly between £100 and £400. Investigators suspected these were payments for fraudulent records.
The payment pattern matched the reported price range for the false vaccine entries. Taken together with the system records, IP address findings and phone evidence, it helped investigators build the case.

The NCA condemned the abuse of healthcare systems
Deputy Director Paul Foster, Head of the NCA’s National Cyber Crime Unit, said:
“These men cynically abused our healthcare system for financial gain, at a time when the country was going through the turmoil and pain of the Covid 19 pandemic.”
The wording reflects the seriousness of the offence. False medical records are not victimless. They can weaken trust in health systems, put pressure on staff and create risks for settings that depend on accurate information.
During the pandemic, vaccination records played a role in decisions about movement, care and public health controls. Fraudulent entries could allow unvaccinated people to appear vaccinated when travelling, working in healthcare or attending large events.
The case also highlights the growing overlap between cyber crime and public services. The fraud relied on system access, identity checks, payment trails and digital communications. It was investigated not only as a healthcare matter, but as a cyber-enabled crime.
Why false vaccination records matter
Some may see a false vaccine passport as a personal shortcut. The wider impact is more serious.
False records can:
Distort official health data
Undermine trust in NHS systems
Put employers and venues at risk of relying on inaccurate information
Expose patients’ personal details
Create unfair pressure on legitimate staff and services
The Fake Covid 19 Vaccination case is a reminder that health records must be treated as high-value data. They can affect legal rights, employment decisions, clinical decisions and public safety.
This is especially true when staff members have privileged access. Administrator rights exist so trusted people can keep services running. When that access is misused, the harm can spread quickly.
What this case means for public sector data security
The outcome also points to the value of audit trails. In this case, suspicious recordings, IP address links, phone evidence, financial deposits and cash seizures all helped connect activity across different parts of the fraud.
For public bodies and healthcare providers, the lessons are clear:
Unusual entry patterns should be reviewed quickly
Staff should understand the consequences of misusing systems
Patient information must be protected at every stage
Digital records should have clear logs that can support investigations
No system can rely on trust alone. Strong records, regular checks and clear reporting routes all matter.

A serious warning from a pandemic-era crime
Hanif and Nasir pleaded guilty and have now been sentenced. Hanif will serve three years in prison. Nasir’s ten-month sentence has been suspended for one year.
The case stands out because of its scale, with more than 2,000 fraudulent documents created in around four months. It also stands out because it involved trusted access to an NHS recording system during one of the most difficult periods in recent public life.
The takeaway is simple. False health records are not harmless paperwork. They can damage public trust, expose private data and create real-world risks. When digital systems carry sensitive information, abusing access to them can lead to serious criminal consequences.
This article is for general information only and is not legal advice.






Comments