US telco SIM registration surveillance APAC

Pakistan's Iris-Scan SIM Proposal Shows the Flaw in Biometric Registration: Stronger Credentials Don't Fix Leaky Enrollment

Pakistan wants iris scans on top of fingerprints for SIMs. The US SIM-swap rules of 2023 offer a narrower model that avoids a national biometric checkpoint.

Biometric SIM Rules: The Numbers People of Internet Research · US 1.83M Illegal SIMs blocked, 2026 Blocked by Pakistan's PTA in the f… 18.2M Illegal SIMs blocked, 2.5 years Cumulative illegal SIMs blocked, a… 30 days Vietnam verification window Time users get to complete face ve… peopleofinternet.com
Biometric SIM Rules: The Numbers People of Internet Research · US 1.83M Illegal SIMs blocked, 2026 18.2M Illegal SIMs blocked, 2.5 yea… 30 days Vietnam verification win… peopleofinternet.com

Key Takeaways

The case for Pakistan's proposal

The strongest argument for adding iris scans is that the current system is failing on its own terms. Minister of State for Interior Tallal Chaudhry told the National Assembly Standing Committee on Interior that the existing biometric system had become obsolete, and that Pakistan would have to move to facial and iris verification. According to Biometric Update's report, the Pakistan Telecommunications Authority (PTA) says about 1.83 million illegal SIMs were blocked in the first seven months of 2026. Officials say stolen fingerprints keep enabling fraudulent registrations.

Dawn's account of the committee hearing gives the mechanics. Criminals are reportedly obtaining fingerprint data from airports, driving-licence centres and passport offices, and possibly from NADRA, the national database. The PTA chairman acknowledged that the biometric system meant to secure SIM issuance was being bypassed. Dawn also reports that about 18.2 million illegal SIMs were blocked over roughly two and a half years, and that illegal SIMs feed banking fraud. Fraud on this scale is a real harm to real people, and a regulator that ignores it is not doing its job.

Why the proposed fix misses the diagnosis

The reported diagnosis is that fingerprints are being stolen. Fingerprints leak because they are collected at many counters and stored in many databases. Adding iris scans adds a second biometric to the same pipeline. If enrolment points and databases stay leaky, the iris template becomes another asset to steal. A stolen fingerprint can never be reissued, and neither can an iris.

The measures Dawn reports the committee discussing are less invasive and probably more effective. They include SMS alerts when multiple SIMs are issued against one national ID number, a cap on SIMs per person, and restricting each SIM to a single device identifier. These act on the fraud pattern rather than on the credential. They also sit closer to what fraud analysts recommend, which is detecting anomalies after enrolment instead of demanding ever-more-permanent identifiers at the point of sale.

The exclusion costs also deserve weight. Iris and face capture fails more often for elderly people, manual labourers with worn fingerprints, and people with certain eye conditions. Where a SIM is the gateway to banking, health information and government services, a failed scan means exclusion from the digital economy. That is a heavy price for a control that criminals have already learned to route around.

The regional wave

Pakistan is not alone. Vietnam's biometric rules took effect on April 15, 2026, following a circular issued on March 31. According to Biometric Update, registration requires a name, date of birth, national ID number and face biometrics, checked against national population databases. Carriers must block outbound service when a device change is detected, and users have up to 30 days to complete verification before full suspension. Indonesia has likewise moved to require biometric verification for SIM registration in 2026, and South Korea and Thailand run identity-linked SIM regimes of their own. The governing logic is the same everywhere. A state ID database becomes a checkpoint for basic connectivity.

That design ties a communications identifier to a national identity record. It is centralised, hard to audit from outside, and attractive to attackers and to future governments with different priorities. Its exclusion risk is systemic, because everyone must pass through the same gate.

What the US model does differently

The US approach to the same problem is narrower. In November 2023 the FCC adopted a Report and Order, FCC 23-95, on SIM-swap and port-out fraud. As the FCC's summary states, it requires wireless providers to adopt secure methods of authenticating a customer before redirecting a phone number to a new device or provider, and to immediately notify customers of any SIM change or port-out request. The Federal Register notice adds that providers must offer account locks and maintain clear processes to report and remediate fraud. The rules set baseline outcomes and leave carriers free to choose the authentication method. They do not require any specific biometric or a national ID lookup.

That flexibility is the point. It targets the actual attack, which is taking over an existing number, and it lets carriers compete on methods. It creates no federal database of irises that every prepaid customer must be enrolled in.

What US stakeholders should weigh

US carriers, identity-verification vendors and platforms that rely on phone numbers for account recovery will meet these regimes in two ways. First, roaming and international customers may face biometric gates in the markets above. Second, US policymakers will hear pitches to import the model as an answer to scams and robocalls. Three tests are worth applying before anyone does.

The Electronic Frontier Foundation has argued in the policing context that powerful surveillance tools need robust written policy before they expand. The same principle applies to identity infrastructure. Governments should set limits and oversight first, then deploy.

Bottom line

Pakistan's fraud problem is real, and so is the case for stronger verification. But the evidence in the hook points to leaky enrolment and weak post-registration monitoring, not to a shortage of biometric types. A proportionate response is to secure the collection points, rate-limit SIMs per identity, alert customers, and make any biometric step auditable and accessible. The US SIM-swap framework shows that outcome-based rules can cut fraud without a mandatory national biometric gate.

Sources & Citations

  1. Biometric Update: Pakistan weighs iris biometrics
  2. Biometric Update: Pakistan weighs iris biometrics for SIM registration
  3. FCC: Rules to protect consumers from SIM swapping (FCC 23-95)
  4. Federal Register: Protecting Consumers from SIM-Swap and Port-Out Fraud
  5. Biometric Update: Vietnam face biometrics mandate