Egypt Egypt social media law cybercrime

Egypt Prosecutes Carriers for SIM Fraud, Then Reaches for a Biometric Fix That Outruns the Problem

NTRA referred all four Egyptian carriers to prosecutors over unauthorized SIM registrations, but its biometric mandate treats a KYC failure as an identity-tech problem.

Egypt's SIM Fraud Crackdown, By the Numbers People of Internet Research · Egypt ~700K Unauthorized lines flagged NTRA logged nearly 700,000 mobile … 4 Operators referred to prosecution Vodafone, Orange, e&, and WE were … ~1 month Biometric rollout deadline NTRA gave carriers roughly a month… peopleofinternet.com
Egypt's SIM Fraud Crackdown, By the Nu… People of Internet Research · Egypt ~700K Unauthorized lines flagged 4 Operators referred to pros… ~1 month Biometric rollout deadline peopleofinternet.com

Key Takeaways

A Wrongful Prosecution Becomes a National Scandal

Egypt's National Telecommunications Regulatory Authority (NTRA) referred all four of the country's mobile carriers — Vodafone, Orange, e&, and WE — to the Public Prosecution on August 10, 2026, over SIM lines registered in citizens' names without their knowledge or consent (Daily News Egypt; Telecompaper). The referral did not come out of nowhere. It followed the case of a university student, Amr Emara, who discovered that a mobile number registered under his identity — without his knowledge — had been used in a drug-trafficking investigation, resulting in a 25-year prison sentence handed down in absentia (Egypt Independent). That case triggered a wave of citizens checking their own records and discovering lines they never opened. NTRA's chief executive, Mohamed Shamroukh, has said the regulator has logged roughly 23,000 complaints tied to nearly 700,000 mobile lines that citizens say they never registered (TechnoTime).

What NTRA Actually Ordered

A day after the prosecution referral, NTRA announced a package of emergency measures aimed at the four carriers:

Citizens can also request a list of every line registered to their national ID and file a "non-possession" form to suspend an unauthorized line, and NTRA has clarified that having a line registered in your name does not, on its own, make you legally liable for how it was used.

The Case for Cracking Down

It is worth stating the regulator's case at full strength before critiquing it. Corporate bulk-registration channels — the ones NTRA has now frozen — let a company buy blocks of SIMs and assign them to employees or clients with minimal individual verification, and that is precisely the gap fraudsters exploited to register lines against real Egyptians' national ID numbers without their presence or signature. The Emara case shows what is at stake when that gap goes unpoliced: an innocent person facing decades in prison over a phone number he never touched. SIM fraud is also a well-documented vector for account takeover, since a hijacked or fraudulently issued line can defeat SMS-based two-factor authentication on banking and social media accounts. Referring carriers to prosecutors for tolerating a KYC (know-your-customer) failure at this scale is legitimate, proportionate enforcement of rules that already existed — not a new speech-restricting law, and not mission creep by the regulator.

Why the Biometric Leap Is a Different Question

Where NTRA overreaches is in treating a paperwork-verification failure as an identity-technology problem. The fraud here happened because corporate registration channels accepted forged or incomplete documentation — not because carriers were checking IDs instead of faces. A September 2025 court case had already surfaced forged signatures on Orange Egypt contracts, which is direct evidence that the carriers' existing document-based verification was broken before biometrics entered the conversation (Egypt Independent). Handing those same carriers a far more sensitive class of data — facial biometric templates, which cannot be reissued the way a password or a document can — does not obviously fix a process failure; it just raises the cost of the next one. The digital-rights group SMEX has flagged this exact asymmetry, and researchers at the Egyptian policy group Masaar have published a dedicated paper arguing for non-biometric alternatives precisely because biometric data collection introduces new, largely irreversible risk without addressing why the paperwork checks failed in the first place (SMEX).

A Narrower Fix Is Available

None of this argues against enforcement — the prosecution referral and the suspension of unverified corporate bulk sales are the right instruments, aimed at the actual point of failure. What doesn't follow is defaulting an entire national subscriber base into facial recognition on a one-month clock, administered by the same four companies whose verification processes just failed at scale. A narrower path exists: tighten and audit the document-based registration process the fraud actually exploited, impose real financial liability on carriers for lines proven fraudulent, and let Egypt's Personal Data Protection Center — the independent body created under Law No. 151 of 2020 — review any biometric rollout for necessity and proportionality before it becomes the default rather than an opt-in convenience. Egypt is right to go after carriers that let this happen. It should not let the fix outrun the problem it was meant to solve.

Sources & Citations

  1. NTRA — official announcement
  2. Digital Policy Alert — Egypt Telecom Law No. 10/2003
  3. Daily News Egypt
  4. Telecompaper
  5. Egypt Independent
  6. SMEX
  7. TechnoTime
  8. CairoScene