A Registry Fined for the Fraud It Was Built to Prevent
On July 16, 2026, Pakistan's Telecommunication Authority (PTA) fined Jazz, Zong, Ufone and Telenor Pakistan a combined Rs740 million (roughly $2.7 million) after finding that operators had issued and activated SIM cards against subscribers' Computerized National Identity Card (CNIC) numbers without their knowledge, consent, or physical presence. Ufone took the largest hit — more than Rs233 million across separate cases — while Zong, Jazz and Telenor were each fined between Rs117 million and Rs156 million. PTA's investigation found operators had failed to enforce Live Finger Detection and geofencing controls on the biometric devices meant to stop exactly this kind of spoofing, and rejected operators' argument that independent franchisees, not the licensed carriers, bore responsibility (TechJuice).
This is not a story about lax regulation. Pakistan has run one of the world's most aggressive biometric SIM regimes since 2015, layering multi-finger verification on top of a national identity database of over 200 million citizens. The fines show the opposite problem: even a mature, centralized, biometrically-linked registry with statutory enforcement teeth gets defeated at the point of sale, where a franchise employee with device access can activate a SIM against someone else's CNIC in minutes.
The UK Is Building the Same Chokepoint
The UK's Fraud Strategy 2026–2029, published March 9, 2026, commits the government to "develop options to create a secure digital tool to manage UK telephone numbers," building what it calls "a centralised repository that provides real-time information on the status and ownership of numbers" (GOV.UK, Fraud Strategy 2026–2029). On July 15, 2026 — one day before Pakistan's fine — the Home Office opened a formal call for evidence on "Anonymous Access to Phone Numbers and Call Routing for Fraud," explicitly asking whether the UK should impose "enhanced Know Your Customer" checks and other identity requirements to close what it calls "weak identification checks" on UK numbers. The document is candid about the stakes: fraud now accounts for 46% of all crime recorded in the Crime Survey for England and Wales (year ending December 2025), at an estimated economic and social cost of £14.4 billion (GOV.UK Call for Evidence).
That case deserves to be taken seriously. Fraud is Britain's largest volume crime by a wide margin, much of it originates over spoofed or anonymously-acquired phone numbers, and law enforcement genuinely struggles to trace calls back through interconnected carrier networks. A centralized numbering tool that lets Ofcom and providers see who currently holds a number and flag suspicious reassignment patterns is a proportionate, narrowly-scoped response to a real and quantified harm — closer to a phone-book with an audit trail than a surveillance database, if it's built and scoped that way.
Where the Analogy Bites
But "if it's built and scoped that way" is doing enormous work, and Pakistan's biometric registry is the closest real-world precedent the UK has for what happens when it isn't. Pakistan didn't fail because it lacked a central database — CNIC-linked SIM records have sat in a national repository for over a decade. It failed because the compliance burden and the point of vulnerability sit in different places: national operators are legally liable, but SIM issuance actually happens at thousands of franchise counters where an employee, not the operator's compliance team, controls the biometric device. Centralizing the record did nothing to fix the incentive gap at the point of activation — it just meant that when the system was defeated, the resulting identity-to-number linkage was wrong at national scale rather than locally.
The UK's planned tool inherits the same structure. A centralised registry of number ownership, tied — even loosely — to identity verification requirements, creates a single high-value target and a single point of failure, administered through a chain of telecom retailers, MVNOs and resellers whose incentives to get onboarding right are weaker than the operators nominally accountable for them. EFF has separately documented how the UK's parallel push into age-verification infrastructure under the Online Safety Act already treats "there is no perfect, privacy-protecting verification service" as an inconvenient footnote rather than a design constraint, warning that identity data collected for one stated purpose routinely outlives it and exposes vulnerable users when it leaks (EFF). A number-ownership database sits on the same trajectory: useful in principle, but only as safe as its weakest onboarding point, and Pakistan just spent Rs740 million demonstrating how weak that point can be even under a mature enforcement regime.
The Fix Is Liability, Not Architecture
The lesson for Westminster isn't to abandon number traceability — it's to keep the coming Call for Evidence focused on where PTA's enforcement actually bit: operator liability for retail-level onboarding failures, mandatory technical controls (Pakistan's Live Finger Detection is a reasonable model) at the point of sale, and audit requirements that catch spoofed activations before they scale, rather than a fresh centralized repository whose breach or misuse risk grows with every number it holds. Ofcom should design the traceability tool to answer "was this call routed legitimately" rather than "who owns this number and where do they live," and Parliament should legislate strict data-minimization and retention limits before, not after, the tool goes live. Pakistan shows what happens when enforcement infrastructure outruns retail-level accountability. The UK still has time to sequence it the other way round.