Pakistan Tech
PTA Introduces Facial Verification for SIM Cards in Major Fraud Crackdown

The Pakistan Telecommunication Authority (PTA) announced plans to implement facial and iris recognition technology for SIM card issuance, marking a fundamental shift away from the fingerprint-based biometric system that has become compromised by widespread data theft. The move follows revelations that criminals are accessing stolen fingerprints from government agencies and exploiting them to obtain fraudulent SIM cards used in identity theft and financial crimes. The decision came during a National Assembly Standing Committee on Interior and Narcotics Control meeting held September 3, 2026, where lawmakers directed authorities to strengthen verification technologies and coordination across telecom, banking, and law enforcement sectors.
A Biometric System Under Siege
The current fingerprint-based verification system, long considered state-of-the-art for SIM issuance, has been decisively compromised. PTA Chairman retired Major General Hafeezur Rehman told the National Assembly committee that scammers are obtaining fingerprints from multiple government touchpoints: airport security lines, driving license centers, passport offices, and potentially even NADRA (National Database and Registration Authority) facilities. The scale of biometric data theft is staggering. During joint operations between the PTA and National Cyber Crime Investigation Agency (NCCIA), authorities recovered biometric data belonging to 600,000 individuals from raided facilities. This stolen biometric data is then sold or rented to criminals who use it to obtain SIM cards under false identities. State Minister for Interior Tallal Chaudhry was blunt in his assessment: the existing fingerprint verification system is "outdated" and has failed to prevent identity and financial fraud despite years of enforcement efforts and billions in penalties levied against cellular operators.
18.2 Million Illegal SIMs Blocked—Yet Fraud Continues
The scale of the PTA's crackdown underscores the severity of the problem: Between July 2025 and June 2026 alone, the PTA blocked 768 mobile numbers and 707 IMEIs associated with fraud. Additionally, 11 CNICs (computerized national identity cards) were blacklisted in connection with fraudulent activity. Over the past two and a half years (January 2024 through August 2026), the PTA has blocked a cumulative 18.2 million illegal SIM cards through various interventions. Of these, 7.9 million were detected through pattern-based analysis, 2.1 million were linked to Afghan ACC or POR card holders, and 8.2 million were associated with cancelled, impounded, deceased, or expired CNICs. During the same period, the PTA conducted 90 raids across 40 cities against illegal Pakistani SIM operations, seizing over 29,346 SIMs, 234 biometric devices, and approximately 602,000 paper-based digital fingerprints. These raids resulted in 134 arrests. Against international illegal SIMs, the PTA and NCCIA conducted 25 raids, recovering more than 8,000 international SIM cards and leading to 37 arrests. Despite this enforcement blitz, fraud has not abated. A single suspect arrested during a Multan raid was found carrying 195 active SIM cards, 16 mobile phones, and 81 bank ATM cards—evidence of a supply chain where fraudulent SIM cards feed directly into financial crime infrastructure.
A Supply Chain of Crime
The problem is systemic. Fingerprints are stolen from government facilities, sold to criminals, used to obtain fraudulent SIM cards, which are then used to open fake bank accounts, which are themselves rented out to scammers for money laundering. NCCIA Director Irfanullah Khan told the committee that criminals are exploiting gaps in both the SIM issuance system and banking channels. Fraudsters now routinely rent bank accounts from individuals—a practice that allows proceeds from scams to move faster than victims can report the fraud and banks can freeze accounts. The committee emphasized that unauthorized withdrawals from victim accounts and the slow pace of freezing or recovering fraudulently moved funds represent a critical weak point. Money stolen through fraudulent SIMs is often transferred out of the banking system before victims even realize they've been defrauded.
Facial and Iris Recognition: The Next Generation
To break this cycle, PTA and the government are proposing a multi-layered upgrade: Facial verification for SIM issuance: Replacing or supplementing fingerprint biometrics with facial recognition, which is harder to spoof with paper, silicon, or nylon reproductions. Iris recognition as a secondary verification method: Iris patterns are highly unique and nearly impossible to duplicate or steal passively. Centralized blacklisting of SIM sale channels: Retailers and outlets involved in irregularities will be tracked and restricted from selling SIMs. Rationalization of SIM sale channels: Tighter control over which retailers can activate mobile connections. Enhanced duplicate SIM controls: Stricter limits on how many SIMs can be issued to a single customer to prevent obvious fraud patterns. The facial and iris recognition approaches are not theoretical. Facial recognition has been deployed successfully in border control, banking, and law enforcement applications globally. However, implementation at scale across Pakistan's telecom network will require significant infrastructure investment and training.
Additional Measures Being Implemented
Beyond facial verification, the PTA is deploying a suite of immediate technical controls: Geofencing SIM-sale devices: Devices used to issue SIM cards are now restricted to within 100 meters of their designated sale location, preventing unauthorized movement to informal locations where fraud is easier. Enhanced Live Finger Detection: The system has been upgraded to block SIM issuance through fake fingerprints made from paper, silicon, and nylon—the primary spoofing methods criminals use. Restricted SIM-sale hours: SIM sales are now prohibited between midnight and 6 a.m., reducing opportunities for overnight fraud operations. Extended SIM disowning period: The window for reporting fraudulent SIM issuance has been extended from 60 days to 365 days, giving victims a full year to dispute unauthorized SIM activations.
PTA Fines and Penalties
The enforcement effort has carried financial consequences. The PTA has imposed penalties totaling Rs. 4.2 billion on cellular mobile operators for violations including fake fingerprints, unauthorized movement of SIM-sale devices, and misuse of biometric verification. This represents significant pressure on operators to improve their compliance systems.
Coordination Mandated
he National Assembly committee directed Interior Secretary Ahmad Raza Sarwar to convene immediate meetings bringing together: Pakistan Telecommunication Authority (PTA) National Cyber Crime Investigation Agency (NCCIA) State Bank of Pakistan (SBP) Cellular mobile companies NADRA The secretary was instructed to submit a comprehensive report on coordinated legislative, regulatory, and technical measures to strengthen Pakistan's cybersecurity framework. The committee also called for instant customer alerts whenever a new SIM is issued in a person's name, a simple measure that could catch fraudulent issuances before they're used for crimes.
Alternative Proposal: PAKID System
The PTA has also proposed allocating SIM cards exclusively through NADRA's PAKID (Pakistan ID) digital system, which already maintains government-verified identity information. This would centralize SIM issuance through a trusted authority rather than relying on retail outlets where security is variable. Similarly, State Bank of Pakistan officials were advised to restrict each SIM to a single IMEI number, preventing a single fraudulent SIM from being used across multiple devices. Banking Coordination and Account Freezing The committee emphasized that banks need to act faster when fraudulent SIM usage is detected. Currently, scammers move money through the banking system faster than victims and banks can react. Proposals include: Immediate freeze protocols when multiple unauthorized transactions occur Faster recovery procedures when fraud is confirmed Better coordination with law enforcement on account rental schemes
Why Biometric Systems Failed
The fundamental problem is that biometric data, once captured, becomes a permanent liability. A fingerprint cannot be changed like a password. If a government database containing fingerprints is accessed—whether through hacking, insider threats, or careless handling—that data circulates indefinitely. Facial and iris recognition face similar challenges theoretically, but are harder to exploit practically. Facial recognition requires capturing someone's face—either through photos or in person. Iris patterns are uniquely difficult to obtain without direct cooperation or specialized equipment. Neither can be easily stolen from government documents the way fingerprints can be extracted from paper records or stored digital files.
Timeline and Implementation
The PTA has not announced a formal timeline for facial verification deployment, though the National Assembly committee's directive suggests urgency. Implementation will likely proceed in phases: Near-term: Enhanced Live Finger Detection, geofencing, PAKID integration (weeks to months) Medium-term: Facial recognition pilots with cooperative cellular operators (months to quarters) Long-term: Full facial and iris recognition rollout across all SIM-sale channels (quarters to years)
International Context
Pakistan's problem with SIM-based fraud is not unique. Countries worldwide have grappled with biometric bypass attacks. However, Pakistan's situation is complicated by the scale of biometric data leakage and the integration of SIM fraud into organized financial crime networks. What remains clear is that fingerprint-based verification, once considered cutting-edge security technology, is no longer adequate for an environment where criminals routinely access stolen biometric data from government facilities. The transition to facial and iris recognition represents an acknowledgment that security technology must continuously evolve as attackers develop new bypass methods. For Pakistani citizens, the transition offers hope of reduced fraud risk. For scammers who have built sophisticated SIM-fraud supply chains, it represents an existential threat to their operational infrastructure. The race is on to see which side—enforcement or criminals—adapts faster.
Sources
TEKZARO


