Egypt Tightens SIM Registration Amid Data Misuse and Identity Theft Concerns

Imagine being summoned to court because of messages sent from your phone that contain insults and defamation directed at someone you’re in a dispute with, although you’ve never sent that person a single message. 
This is the story of a woman living outside of Egypt in 2024. It later emerged that the person in question had used a copy of the woman’s ID to obtain a replacement SIM card for her number, and then sent insulting and defamatory messages to himself from that number and filed a lawsuit against her.
The same thing could happen to any Egyptian citizen amid growing complaints from users who have reported that phone numbers have been registered using their personal data without their knowledge. 
This prompted Egypt’s National Telecommunications Regulatory Authority (NTRA) to refer the four mobile operators operating in the country to the Public Prosecutor’s Office on Monday, August 10, 2026, to investigate allegations of phone lines being registered using citizens’ data without their knowledge or actual possession of such data. 
The authority stated that it had conducted inspections and investigations and gathered the relevant evidence, clues, and documents.
The reason behind this “loophole” that allowed some citizens to obtain phone numbers using the data of other citizens is still unclear. It is suspected to be either negligence from company employees, an organized network facilitating such activities, or other possibilities. 
The statement did not specify the number of lines or the number of affected users. In any case, this issue is no longer limited to a mere procedural violation; it also concerns the protection of personal data, as registering a line in a person’s name without their knowledge could lead to the use of their data in illegal communications or activities, which carries significant consequences.
Exceptional Measures Increase Privacy Risks
Following its meetings with the four companies—Vodafone Egypt, Orange Egypt, e& Egypt, and WE, the Authority approved urgent measures to overhaul the line registration system and verify the identities of the actual line holders, namely:

  • Suspending the sale or activation of new lines through the companies’ systems to entities and institutions
  • Requiring companies to send messages to existing lines registered in their systems, inviting their holders to sign new contracts in their own names
  • Canceling lines for which the contracting procedures are not completed within the specified deadline.

The Authority also directed companies to expedite the implementation of biometric verification mechanisms for line holders via electronic applications, which will also allow citizens to identify numbers registered in their names without their knowledge and take the necessary action regarding them.
The move toward biometric verification may make some forms of identity theft more difficult, but it also introduces highly sensitive data into the registration process, according to Mohammed Al-Taher, a technical researcher at “Masaar.”
Biometric data, such as fingerprints or facial features, differs fundamentally from an ID number or phone number. Unlike traditional identifiers, which can be changed if leaked or misused, biometric characteristics cannot easily be replaced.
Therefore, increasing reliance on these mechanisms poses greater challenges in terms of their protection, which opens up a debate about how biometric data is collected, stored, and protected; which entities have access to it; how long it is retained; and whether there are sufficient safeguards to prevent its use for purposes other than those for which it was collected.
These measures come in the context of an issue that has already reached the Egyptian courts: in September 2025, the North Cairo Court of First Instance ruled to rescind and invalidate a contract for the purchase of a mobile phone line from “Orange Egypt” after it was proven that the data subject’s signature on the subscription contract had been forged, according to Masaar. This case raised questions about the adequacy of the verification mechanisms used by companies to ensure the accuracy of subscriber data.
An Increased Oversight on Mobile Companies
The new decision places greater responsibility on mobile companies to verify subscriber identities and properly manage user data. Identity verification is no longer just a step at the point of sale; it is part of a broader system designed to ensure that registration data matches the actual subscriber. 
The authority may take legal and administrative action against companies that fail to comply, including suspending the sale or activation of new lines and referring violations to the public prosecutor. The measures therefore test companies’ ability to address gaps in existing databases and prevent unauthorized registrations, while making data protection a shared responsibility between companies, regulators, and users.
The decision is significant because it shifts the current model to a more comprehensive one that relies on the continuous verification of the line holder’s identity. This is a major shift because it extends the responsibility of telecommunications companies beyond the moment of sale and places user data protection and identity verification at the heart of telecommunications sector oversight.
The post Egypt Tightens SIM Registration Amid Data Misuse and Identity Theft Concerns appeared first on SMEX.