TL;DR: Since July 1, 2026, biometric SIM card registration has made it harder to register phone numbers using fake identities. However, it only answers who owns the number at the time of registration, not who is using it afterward. Fraud through OTP theft, malware, and SIM swaps can still target legitimate identities.
Since July 1, 2026, every new SIM card in Indonesia has been required to be linked to the owner's biometric data, particularly facial data. The policy comes amid increasingly complex forms of digital crime, ranging from spam calls and OTP theft to phishing, identity misuse, and the use of anonymous SIM cards for illegal activities.
What is biometric SIM card registration and why is it necessary?
Biometric registration is the process of linking a mobile phone number to its owner's identity through biometric data, such as facial recognition. The goal is to ensure that a mobile number is genuinely linked to the identity of its rightful owner.
Is it safe to register a SIM card using a facial scan?
Yes. Biometric data is only used to match the user's identity at the time of registration. Customer biometric data is not stored by the mobile operator. The verification process matches the user's face against an authoritative database using international ISO security standards and liveness detection technology.
In principle, this approach is designed to prevent the creation of a new centralized facial database. The process therefore focuses on verifying and matching the user's identity.
Is Biometric Registration Enough to Stop Fraud?
For now, it is not enough, because registration only verifies who owns the number at the time of registration, not who is using it afterward.
The Indonesia Anti-Scam Centre recorded 432,637 fraud reports from its establishment in November 2024 through January 2026, with total reported losses reaching IDR 9.1 trillion. Data from IASC and the PASTI Task Force through April 2026 also recorded approximately IDR 9.5 trillion in reported losses from cybercrime.
Biometric SIM card registration essentially links a phone number to its owner's identity through biometric verification. When someone registers a SIM card, their identity is not only recorded based on the information they provide, but also verified through biological characteristics unique to them. This makes it harder to use a fake identity to register a number.
However, registration only confirms who owns the number at the time of registration. Several other forms of fraud can still occur:
1. OTP Takeover Through Social Engineering
The number is registered using a valid identity, but fraudsters trick the victim through social engineering into handing over an OTP. They typically impersonate a bank, courier, mobile operator, or other legitimate service provider.
Download VIDA whitepaper to know more about account takeover
2. OTP Takeover Through Malware
Malware is often delivered through illegal applications downloaded from untrusted sources. Once a device is infected, certain types of malware can read SMS messages, access notifications, or exploit device permissions to capture OTPs. Fraudsters can then use the codes to proceed with login or authentication.
3. SIM Swap
Fraudsters use personal data leaked from other sources to impersonate the phone number's rightful owner, then take over the SIM card. They can use it to hijack connected banking accounts, social media accounts, or other digital services.
The Role of Digital Infrastructure in Securing Mobile Phone Numbers
A mobile phone number is more than just a communication tool. It has become a gateway to bank accounts, digital wallets, and almost every important online account. This is where the role of digital identity infrastructure extends beyond simply securing the SIM card registration process.
Once a person's identity has been verified, the threat does not stop there. Systems need to be able to detect signs of fraud when a verified identity is used to log in and conduct transactions. There are four key layers that make up a strong digital identity infrastructure:
The first layer ensures that the person being verified is a real human. Liveness detection ensures that the face appearing on camera is not a photo, video, or other form of manipulation.
The second layer ensures that the face is linked to a legitimate identity. During SIM card registration, the user's face is matched against official population data to ensure that the number is linked to the rightful identity owner.
The third layer ensures that the verification process takes place through the user's legitimate device. The system needs to identify whether verification is being performed from a suspicious device or environment, including attempts to manipulate the process through injection attacks or unusual device changes, such as when the same phone number is suddenly accessed from an emulator, a rooted device, or a location manipulated through GPS spoofing.
The fourth layer continuously monitors activity after verification. Fraud is not always visible when an identity is first verified. Systems therefore need to monitor logins and transactions to identify anomalous or suspicious account activity patterns.
These layers show that identity verification should not happen only once at the beginning. Ultimately, biometric registration is just one of many steps toward building a stronger digital identity security ecosystem.