The case for the rules
The strongest argument for South Korea's tougher phone-activation checks is that the problem is real and large. According to the Korea JoongAng Daily, voice-phishing losses passed 1 trillion won for the first time, reaching about 1.13 trillion won across 21,588 reported incidents as of November 2025. Burner phones, known locally as daepoppon, are the plumbing of that crime, and they are opened with stolen or forged identity documents. A system that only inspects a plastic card at the counter invites exactly that abuse. The data-theft backdrop makes it worse: the Ministry of Science and ICT's final investigation found roughly 26.96 million IMSI records exposed in the SK Telecom breach. Regulators who respond are not being frivolous.
What actually changed on July 6
Since July 6, 2026, anyone opening a new line or porting a number must add one of three verifications on top of showing an ID, according to the Korea Times: facial recognition, the Interior Ministry's mobile ID app, or a resident registration extract issued the same day. Customers who only swap handsets on the same carrier are exempt. The rules apply in carrier stores, at third-party retailers and online.
The design deserves credit. The government originally planned mandatory facial recognition. The Korea Times reports that the Personal Information Protection Commission and the National Human Rights Commission of Korea recommended offering a choice because biometric data is sensitive, and the final rule did so. The Ministry says no original facial images are stored and that biometric data is used only for matching and then discarded. Ministry security chief Choi Woo-hyuk told the JoongAng Daily that facial data is "encrypted, held for 0.04 seconds and then immediately destroyed," and that the Korea Internet & Security Agency's preliminary check found no leak vulnerabilities. Those are claims from the government and its own agency, not independent audits, but offering a non-biometric path is the right instinct.
Where the gatekeeping appears
In the weeks after the rules took effect, the carriers' PASS app became the practical centre of the system. SK Telecom, KT and LG Uplus run it jointly, and the facial-verification scheme builds on it. Facial recognition is one route and the ministry-run mobile ID is another. The third route, the same-day resident registration extract, means a trip to a government office or an online request, and that is a real friction cost for anyone without a smartphone or a mobile ID.
The QR campaign shows how verification infrastructure grows. According to Mobile ID World and Digital Today, the three carriers launched "QR Once, Double the Peace of Mind" on August 31, running to October 5. It urges people and merchants to scan the QR code on a PASS ID instead of glancing at the screen. The carriers say people are faking IDs with apps that imitate a mobile ID screen or with composited images. A QR scan checks that the credential belongs to the device it was issued to, blocks screenshots, uses moving imagery and expires after a short time. There are 2,076 prizes, topped by a Galaxy Z Fold8.
This is a private initiative, not a mandate, and the security logic is sound. A moving, device-bound credential is harder to forge than a screenshot. But the campaign shows the direction of travel: once a state-backed check depends on a handful of apps, forgers target those apps, and the fix is more reliance on those apps. A forged screen is only a problem if someone trusts a screen. That is a case for scanning the credential, not for making the app compulsory.
Why concentration is the real risk
Three things should worry a pro-innovation, pro-privacy reader.
- The fallbacks are thin. The Korea Times reports that people who cannot or will not use facial recognition can proceed through alternative methods leading to conditional activation, but the rules do not make clear how routine or fast those paths are. An option that takes a day is not an option for the person who needs a phone today.
- The legal footing is still being built. The Korea Times reports regulatory amendments are planned by October to firm up the framework. Rules applied first and legislated afterward invite scope creep, where a telecom anti-fraud check becomes a general-purpose identity layer.
- The breach history cuts both ways. The same carriers that run PASS were the subject of the SK Telecom breach, which MSIT attributed to plaintext credential storage and failure to follow up on a 2022 anomaly. Handing identity checks to operators with that record is defensible only with independent security audits.
Privacy advocates, quoted by the JoongAng Daily, pointed to China's 2019 face-authentication rollout, where collected facial data later turned up for sale online, and noted that matching can fail because of outdated ID photos or changes in appearance. No such leak has been reported in Korea, but that is the failure mode to design against.
What proportionate looks like
Korea should keep the choice at the centre of the rule, and write it into the October amendments. Three steps would do it:
- Put the non-biometric routes in the legal text, with a fixed turnaround for conditional activation so that choosing not to scan a face never means going without a phone.
- Require independent, published security audits of any app that serves as an official verification route, not a preliminary agency check.
- Keep QR and device-bound credentials as a security feature that merchants can adopt voluntarily, not a gate that individuals must pass to buy a basic service.
The carriers' campaign is a sensible response to forgery. The lesson for policymakers is to keep identity checks narrow, optional where possible and auditable, so the apps that carry them do not become the only way in.