Almost every business in America treats a mobile number as proof of identity. It receives the one-time passcode that opens the payroll account. It confirms the wire transfer. It resets the password when an executive is locked out at 11 p.m. Very few companies have ever asked the obvious follow-up question: what actually guarantees that the number belongs to the person answering it?
In the United States, the honest answer is a carrier record and a customer service call. In some other countries the answer is a biometric registry, checked against a national ID at the moment the line is sold.
Pakistan runs a national SIM database of exactly that kind at a scale nobody else has matched, and what its citizens can see of their own records explains the system better than any policy document. Its results over the past two years are the closest thing risk managers have to a controlled experiment.
The findings are not what most executives expect. A stronger identity check at the point of sale did not eliminate fraud. It moved it. Understanding where a SIM database stops working, and what SIM information it will and will not release, is worth more to an Arizona business than another lecture about password hygiene.

Three custodians hold a national SIM database between them, and none offers a public lookup.
What a SIM Database Actually Is
The term gets used loosely, so it helps to be precise. A national SIM database is the registry that links each activated mobile connection to a verified human being. In Pakistan the anchor is the Computerized National Identity Card, issued by NADRA, the national identity agency. In India it is Aadhaar. In Nigeria it is the National Identification Number.
What makes the Pakistani version worth studying is the enforcement. Buying a new line, getting a duplicate, changing ownership, porting a number to another carrier, re-verifying and disowning all require a live fingerprint check at an authorized outlet. Since December 2022 the hardware layer has been a multi-finger system that picks which fingers to scan rather than letting the retailer pick, and asks for at most two successful impressions.
That is a far stronger enrollment control than a US carrier applies. Walk into a store here and the identity check is a driver license and a credit file. Walk into a store there and it is a live fingerprint matched against a federal database in real time.
The scale is what makes the lesson transferable. Pakistan recorded 204.771 million active mobile connections at the end of February 2026, and every one of them sits inside that registry. Few identity systems anywhere operate at that volume with that level of verification.
The Strictest Registry in the World Still Failed
In July 2026, Pakistan’s telecom regulator fined every mobile operator in the country. The Pakistan Telecommunication Authority, known as PTA, imposed about Rs 740 million in cumulative penalties, roughly US$2.7 million, across the licensees named in its enforcement orders.
The reason matters more than the number. This was not a data breach case. The regulator found that connections had been activated against identity cards whose holders had never visited a shop and never agreed to anything. Franchise and retail networks were poorly supervised. The controls meant to keep biometric hardware honest, liveness detection and geofencing, were not properly enforced.
Read that list again with an American org chart in mind. Nothing there is a cryptography failure. Every item is a supervision failure at a retail counter run by a third party under somebody else’s brand.
PTA also refused two defenses that licensees commonly reach for. The first is that a clean fingerprint match settles the question. It does not, because a match proves a finger touched a scanner, not that the finger’s owner asked for a connection. The second is that a franchise is somebody else’s business. It is not, because responsibility follows the license rather than the storefront.
That second ruling is the one worth pinning above a compliance desk. Outsourcing the transaction does not outsource the liability.
The registry itself has hard limits that make the failure easier to see. A single identity card in Pakistan may hold at most eight connections, five voice and three data, counted across every carrier rather than per carrier. That ceiling was set when the Supreme Court of Pakistan allowed three data lines on top of an existing five-voice limit on 5 November 2015.
Two newer rules tightened the edges further. Under an advisory dated 24 May 2026, a newly activated line cannot be transferred or disowned for 365 days. And since 24 January 2024, the buffer between new sale sessions on the same identity card is seven days rather than eight hours.
Those caps are enforced by the SIM database at the moment of sale, which is exactly what makes the July 2026 findings so instructive. The ceiling held. The counter did not.
When a system knows precisely how many lines a person is allowed and still activates lines that person never requested, the defect is not in the data model. It is in the chain of people between the model and the customer, and every business that relies on a phone number has a version of that chain.
What SIM Information Can and Cannot Prove
Here is where American assumptions usually break. Executives hear national SIM database and picture a searchable directory: type in a number, get back a name. No such window exists, in Pakistan or anywhere comparable, and the reason is deliberate. The SIM information a registry holds and the SIM information it will release are two very different sets.
The record is split across three custodians. Identity and biometric data sit with the national identity agency. Subscriber records sit with the licensed carriers. The regulator, which writes the rules, has stated publicly that it holds no subscriber data at all. Carriers are bound by confidentiality conditions that apply even between companies inside the same corporate group, with narrow carve-outs for debt recovery, service provisioning between operators, a legal obligation, and disclosure with the customer’s prior informed consent.
So the SIM information available to a member of the public is scoped tightly to what they already hold. A citizen can text their own ID card number to a short code, or use the regulator’s free web portal, and learn how many connections are registered in their name on each network. That is the whole of it. No names, no addresses, and nothing at all about anyone else’s number.
This has a direct commercial consequence that gets missed. Any vendor offering bulk SIM information for a South Asian market, or a searchable subscriber database, is selling something that cannot lawfully exist. In Pakistan the relevant statute is the Prevention of Electronic Crimes Act 2016, and Section 16 makes obtaining, selling, possessing, transmitting or using another person’s identity information without authorization a criminal offense. The buyer is exposed alongside the seller.
If a due diligence, collections or marketing vendor offers your company that capability in any emerging market, the correct response is not to negotiate the price. It is to end the conversation and document that you did.

The registry is rarely what fails. The counter, the call center and the payout screen are.
Where SIM Database Fraud Actually Goes
Strengthen the front door and attackers use the windows. Pakistan’s enforcement record over the past two years reads like a map of exactly which windows.
| Enforcement action | Figure | Date |
| Penalties on the cellular licensees over SIM issuance violations | about Rs 740 million | July 2026 |
| Sites, apps and social pages blocked over the sale or sharing of personal data | 1,372 | by September 2025 |
| Platforms identified in a sweep led by the National Cyber Crime Investigation Agency | 139 | October 2025 |
| Citizens’ records compromised in the national identity database, per a joint investigation led by the Federal Investigation Agency | 2.7 million, 2019 to 2023 | March 2024 |
In July 2026, acting on a complaint from PTA, cybercrime investigators in Lahore detained three suspects over an organized network trading call records, registration data and location data. Alongside phones and SIMs, they seized eight biometric verification devices.
Those devices are the whole story in one detail. The leak was not a compromised SIM database. It was verification hardware in the wrong hands, and insiders with access who should not have had it. Almost every batch of SIM information sold illegally in that market traces back to a failure of that shape.
The American version of the same problem has a different name and identical mechanics. It is called SIM swapping, and it does not need a biometric scanner because it does not need a fingerprint. It needs a persuasive phone call to a retention agent. The FBI’s Internet Crime Complaint Center logged 982 SIM-swap complaints in 2024, with about US$26 million in reported losses, and those are only the cases somebody bothered to report.
Four Controls That Actually Work
Strip out the geography and the same four checkpoints appear in every case. Each one is a place a business can act without waiting for a carrier or a regulator.
• Treat the enrollment record as a claim, not a fact. A number that changed hands or changed device in the past 48 hours is among the strongest pre-transaction fraud signals available. That signal reaches a bank through a carrier agreement, under contract and with customer consent, not through a public lookup. If your institution has no such feed, building one is a higher-return project than another awareness campaign.
• Put a cooling-off window on payout changes. Account takeover needs two things to finish: control of the passcode and a new destination for the money. Delaying the second removes most of the value of capturing the first. Twenty-four hours plus an out-of-band notification defeats a large share of real cases.
• Stop treating loss of signal as a support ticket. From the customer’s side, a hijacked number looks exactly like a dead SIM. The help desk is usually where the first evidence of a swap arrives, and usually where it is discarded. Route it to security, not to tier-one support.
• Audit who can issue and who can verify. Pakistan fined an entire market because franchise staff had devices and discretion nobody was watching. The equivalent question in an American company is who can change a customer’s registered number, how that action is logged, and whether anyone reviews the log.
None of these requires a national SIM database, and none of them depends on SIM information you are not entitled to. That is the point. The registry was never the control. It was the record.
What US Regulators Have Already Done
American rules have moved in the same direction, if less dramatically. The Federal Communications Commission adopted rules addressing SIM swap and port-out fraud, requiring carriers to use secure customer authentication before transferring a number to a new device or a new carrier, and to notify customers immediately when such a request is made.
That is meaningful, and it is also narrower than most executives assume. It governs the carrier. It says nothing about what your own company does when a customer calls to change the number on file, which is the step where a great deal of fraud actually completes.
The pattern holds across both countries. Regulators can require an identity check and can build a SIM database to record it. They cannot supervise every counter where that check is performed, and they cannot write your internal procedure for you.
The SIM Information Questions Worth Asking This Quarter
Four questions will tell an executive team more about their exposure than any vendor demonstration.
1. Which internal processes treat a mobile number as proof of identity? The list is almost always longer than anyone expects, and it usually includes payroll, banking, cloud administration and the password reset path for the executives with the most access.
2. What happens when a customer or an employee changes the number on file? Who can approve it, what evidence is required, and is that change reviewed by anyone afterward?
3. Do we buy identity or contact data from vendors operating in markets with strict registration laws? If so, can the vendor show a lawful source? A SIM database or a bulk SIM information product from those markets almost certainly has none.
4. When a customer reports losing service unexpectedly, where does that report go? If the answer is the help desk queue, you have already found something to fix this quarter.
Frequently Asked Questions
The questions that come up most often about how a SIM database works and what SIM information it makes available to a business.
Can a business look up who owns a phone number in a country with a SIM database?
No. Registration systems of this kind are built without a public search window. The identity agency, the carriers and the regulator each hold different parts of the record, and none offers a lookup that turns a number into a name. Law enforcement reaches subscriber data through documented legal process tied to a registered case, and courts reach it through orders.
Are commercial SIM database and SIM information services legitimate?
In markets with mandatory registration, no. A lawful custodian could not sell those records, so any product offering them is reselling breach material, fabricating results, or harvesting whatever the visitor types into the search box. In Pakistan, Section 16 of the Prevention of Electronic Crimes Act 2016 makes obtaining that data without authorization a criminal offense for the buyer as well as the seller.
Does biometric SIM registration stop SIM swap fraud?
It raises the cost of one attack path and leaves others open. Pakistan’s July 2026 enforcement action found lines activated without the holder’s knowledge despite a mandatory fingerprint check, because supervision at the retail counter had failed. Biometrics secure the moment of verification and write clean SIM information into the registry. They do not secure the process around it.
What SIM information can an individual actually obtain?
In Pakistan, a person can send their own 13-digit identity card number to the short code 668, at a cost of about Rs 2, or use the regulator’s free web portal, and receive a count of how many connections are registered against that card on each network. The reply contains no names and no addresses, and there is no route to anyone else’s record.
What should a US company do differently after reading this?
Start by listing every internal process that treats a mobile number as identity, then add a review step to the one that moves money. If the company operates in South Asia or buys data from vendors that do, add a contractual representation that no subscriber data was obtained from an unlawful source, because that exposure travels with the buyer.
The Bottom Line
Pakistan built one of the most rigorous mobile identity systems in the world and then fined every carrier in the country over how it was operated. That is not an argument against strong registration. It is an argument about where the risk lives.
A SIM database records who a number belongs to, and good SIM information makes that record auditable. Neither can supervise the clerk who registered the line, the agent who transferred it, or the process inside your company that trusts it. Those three remain the responsibility of the organization relying on the number, which in almost every case is a business rather than a carrier.
The registry is the easy part. Everything around it is the work.
Author: Muhammad Hamza writes about digital identity, telecom regulation and consumer data rights in Pakistan. He runs CnicSimInfo (https://cnicsiminfo.pk/), a public-interest resource that explains Pakistan’s official SIM verification channels in plain language and keeps a verified-sources policy for every published figure.