A Scandal With Real Victims
On August 10, 2026, Egypt's National Telecommunications Regulatory Authority (NTRA) referred all four of the country's mobile network operators to Public Prosecution over SIM lines registered under customers' personal data without their knowledge or consent. The regulator simultaneously suspended bulk sale and activation of corporate lines, ordered operators to text every existing subscriber demanding an in-branch identity re-verification, and warned that lines left unclaimed past an unspecified deadline would be permanently cancelled. It also accelerated a facial-biometric verification system operators must roll out through their apps.
The scale explains the urgency. NTRA chief executive Mohamed Shamroukh said the regulator had logged around 23,000 complaints covering nearly 700,000 mobile lines registered to people who say they never asked for them — lines apparently sold in bulk through corporate and reseller channels with minimal identity checks, then used, resold, or left dormant while the paper owner remained legally on the hook. Egypt Independent reported that an NTRA spokesperson, Mohamed Ibrahim, drew a line between crimes referred to prosecutors and administrative violations NTRA can handle itself under operators' licensing terms — and stressed that having a stray line registered in your name doesn't automatically make you liable for what was done with it.
The Case For Acting Fast
The strongest argument for NTRA's package is straightforward: unverified SIMs are the raw material of SIM-swap fraud, mobile-money theft, and phone-based scams, and bulk corporate sales are the channel of least resistance for anyone trying to source lines that can't be traced to a real person. A regulator that discovers 700,000 lines potentially mismatched to their true holders has a legitimate interest in shutting off the tap — bulk suspension until identity checks are fixed — and in giving victims a fast way to disown a number registered fraudulently in their name. Facial-biometric matching against national ID photos, done automatically rather than by a company employee, is in principle a more reliable check than the paper-and-photocopy process it replaces. None of this is manufactured outrage; Egyptians were finding phantom SIMs tied to their national ID numbers for months before the referral, per Ahram Online's coverage of the run-up.
Where the Remedy Outpaces the Diagnosis
But the instrument NTRA chose is badly calibrated to the problem it identified. The failure NTRA describes sits upstream — in how operators screened bulk and corporate buyers — yet the burden of the fix falls downstream, on ordinary subscribers who did nothing wrong and now must physically visit a branch before an unpublished deadline or lose service entirely. There is no indication of a grace period tied to actual risk, no distinction between a dormant unclaimed line and one already flagged as fraudulent, and no published appeals process for someone who simply can't get to a branch in time. Mass, deadline-driven re-registration under threat of permanent cancellation is a blunt instrument for a problem NTRA itself traces to bulk sales channels operators controlled, not to millions of individual subscribers.
The criminal referral raises a separate concern. Egypt's regulatory toolkit already includes fines, licence conditions, and administrative suspension — NTRA used exactly that toolkit to freeze bulk corporate sales the same day. Escalating straight to Public Prosecution against all four operators simultaneously, rather than opening administrative proceedings first and reserving prosecution for operators that don't remediate, reads as a signal of political urgency more than a measured enforcement ladder. Egypt's Anti-Cybercrime Law No. 175 of 2018 already gives the state broad authority to compel telecom data disclosure; a prosecution-first posture against license-holders, layered onto that existing surveillance architecture, is the kind of move that deserves scrutiny even when the underlying complaint is legitimate.
The Biometric Shortcut Needs More Guardrails, Not Fewer
The accelerated biometric rollout is the part that most needs independent oversight before, not after, it scales. Egyptian Streets reported an NTRA spokesperson's assurance that facial-matching data "will not be available to mobile companies" and that verification happens by automated match against ID records rather than human review — a real privacy improvement over employee-handled photocopies. But that assurance addresses only operator access, not what the state itself retains, for how long, or under what audit. Shamroukh's own framing — that the digital route is optional and subscribers can still verify in person — is the right instinct, but optionality means little if the alternative is an unstaffed branch queue against a hard cancellation deadline. Egypt's Personal Data Protection Law No. 151 of 2020 exists precisely to answer questions like retention limits and independent audit rights for exactly this kind of centralized biometric matching; NTRA's own announcement is silent on both.
What Proportionate Would Look Like
None of this argues against fixing bulk-sale identity gaps or giving fraud victims a fast disownership channel — both are overdue. It argues for sequencing: publish the re-verification deadline and grace-period criteria now, reserve criminal referral for operators that don't remediate rather than issuing it as an opening move against all four simultaneously, and subject the biometric matching pipeline to the same data-protection audit NTRA is asking subscribers to trust it with. Egypt has real fraud to fix. It doesn't need to borrow enforcement tools from its cybercrime statute to fix it.