Sunday, September 27, 2026

Egypt’s Mobile Line Scandal: Before You Ask for My Face, Explain How You Got My ID Leaked

We are now in the last week of September, and the facial biometric measures have still not been officially rolled out for new and existing mobile phone lines, as announced by Egypt’s National Telecom Regulatory Authority (NTRA).

It is a big step towards digitalisation. It will be an optional step, but I am not taking it any time soon — and I won’t be alone in that hesitation.

Last month, many Egyptians, including yours truly, discovered that we had additional mobile phone lines and mobile money wallets registered under our National IDs without our knowledge through Egypt’s four mobile phone networks.

Yes, you read that correctly.

On 7 August 2026, I discovered through the NTRA’s application, My NTRA, that another mobile phone line — aka a SIM card — was registered to my National ID number on Orange Egypt without my knowledge.

The My NTRA app is available for free on both the iOS App Store and Google Play Store.

I have been a very long-term Orange Egypt customer, going back to when it was still Mobinil, and I had never received any notification that I had this mobile phone number.

I had never received any bills for it, and it had never appeared in the “My Orange” app.

I did once have an internet line from Orange Egypt a long time ago, but it was suspended for inactivity. It was not the same number.

Orange Egypt handles data lines under the same NTRA rules that apply across all Egyptian operators. Since data lines are prepaid, if a line remains unused for 90 days — with no calls, SMS messages or data activity — the operator suspends its service.

Before that happens, however, the operator is required to warn the customer twice: once 10 days before the cutoff and again 48 hours before.

Once the line is suspended, there is still a 15-day grace period to save it, simply by using or recharging it, provided that the customer’s details match those held by Orange.

Only after that 15-day window passes without any action does Orange cancel the contract and release the number back into its pool, where it can be resold to a new customer. At that point, it is gone for good.

That is exactly what happened to the data lines — aka MiFi lines — from TeData, later WE/Telecom Egypt, that I bought over the years to keep working during power outages.

None of those lines appeared to be linked to my National ID anymore.

The mysterious mobile phone line, however, was there — although I could not even see the full number. Only a few digits were displayed. And please do not ask me why.

I was lucky that I found no other mobile money wallet registered under my National ID apart from the one I actually own, which is linked to my bank account rather than directly to my mobile phone line, unlike services such as Orange Cash.

I was even luckier than many other people who discovered three, six, or even 20 mobile phone lines connected to their National IDs.

Even renowned public figures were affected.

Famous television host and journalist Amr Abdel Hamid discovered that 14 lines were linked to his National ID alone.

Abdel Hamid was lucky enough to have them cancelled smoothly.

As a renowned television news host, he was also wise enough to follow the steps recommended by lawyers before approaching the NTRA.

While other people went to branches of Egypt’s four mobile operators seeking explanations within the first 48 hours of the affair, they found themselves involved in confrontations with customer service representatives.

Many of those incidents were filmed and shared on social media, particularly Facebook and TikTok.

From what I have seen and understood, many of the disputes centred on customers’ demands to see the contracts for the unauthorised mobile phone lines and mobile money wallets registered under their National IDs.

That was also something I planned to ask for.

The contracts matter because the terms governing mobile services in Egypt require the customer to appear in person, present the original National ID and sign the contract.

The operators’ terms and conditions also provide for customers to obtain copies of their service contracts for mobile lines registered in their names.

So, the obvious question is: if I supposedly signed a contract for a mobile line, where is that contract?

Some customers said they were told by branch representatives that employees did not have the authority to access or display the contracts or copies of them on their systems.

Other disputes erupted over another issue: what customers should sign to get rid of lines they said they had never owned.

According to accounts circulating at the time, some operators provided customers with forms described as a “waiver”, through which the customer would give up the disputed line and return it to the operator.

This raised concerns among lawyers and legal experts, who warned customers against signing such forms without understanding their legal implications.

Their concern was straightforward: if a customer signs a document that states, explicitly or implicitly, that they are the owner of the line and are merely waiving it, that could create a record appearing to acknowledge ownership — precisely what the customer is trying to deny.

The concern becomes more serious if a disputed line had previously been used in connection with a crime or other unlawful activity.

Lawyers advising affected customers therefore urged them to request a document from the operator explicitly stating that they denied ownership of the disputed line, rather than signing a waiver for a line they said they had never owned.

They also advised customers to document the matter formally, including by filing a report at a police station and submitting the documentation to the NTRA.

There were also disputes at branches involving customers demanding an official document confirming that they had no ownership of the disputed lines, so they could establish that they were not responsible for them.

The NTRA, for its part, said customers should not be held legally responsible for the use of lines that they did not actually purchase or register.

And this is where the whole affair becomes particularly important.

The issue of legal responsibility for mobile lines linked to a person’s National ID was the main thing that turned what initially looked like a bizarre administrative problem into something much bigger.

The case that helped trigger the alarm centres on Amr Abdel Hakim Mohamed Ibrahim, a computer science student at Zagazig University from Abu Kabir in Sharqia governorate.

Amr Abdel Hakim was the reason we discovered this scandal

According to his family, the trouble began roughly two years earlier when a friend asked him to register a mobile line in his name, claiming it was needed to help a relative meet a sales target at a telecom company. The understanding, according to the family, was that the line would remain unused.

That line was later linked to Case No. 172 of 2024, which was tried before the Suez Military Felony Court and involved a shipment of onions allegedly used to smuggle narcotics through the Ahmed Hamdy Tunnel in Sinai.

Unaware of the case, Amr was tried in absentia and, according to reports published around 18 June 2026, was sentenced to life imprisonment. An earlier account had reported a 25-year sentence.

After learning of the verdict, he turned himself in so that his case could be retried.

His family said they discovered the phone line’s role only after hiring a lawyer to review the case files. By early August 2026, they were pursuing a retrial petition and preparing a cassation appeal.

The case prompted some lawyers to start asking a much bigger question: how many other people had mobile lines registered under their National IDs without knowing about them?

And when people started checking, we found ourselves facing something much bigger than a few mysterious SIM cards.

We had uncovered a nationwide affair — if not a scandal.

It is unclear how many mobile phone users were affected, but there were clearly too many for this to be dismissed as a handful of isolated cases. In my own direct circle, only a very small number of family members and colleagues did not find extra lines linked to their National IDs.

According to local news reports published during the first 72 hours of the affair, around 100 citizens filed multiple reports at nine police departments under the Cairo Security Directorate against the four mobile operators after discovering mobile lines and e-wallets registered in their names without their knowledge.

The police departments that received complaints reportedly included those in the Fifth Settlement, Ain Shams and Heliopolis, alongside several other departments. The complainants said mobile lines and e-wallets had been registered using their personal data without their consent.

By the first week, the NTRA said it had received more than 4,000 complaints about mobile phone numbers being registered under citizens’ names without their knowledge, adding that it was continuing to investigate the complaints. The regulator also referred the four mobile operators — Vodafone, Orange, e&, and WE — to the Public Prosecution over lines registered using citizens’ personal data without their knowledge.

According to MP Ahmed Badawy, head of the House of Representatives’ Communications Committee, more than 700,000 text messages had been sent to update customer data and block non-compliant numbers.

The number jumped later.

The four telecom operators began sending text messages to a large number of mobile users, notifying them that their lines had been suspended for failing to provide or update their personal data.

Customers were instructed to visit one of the companies’ branches to verify their registered information and complete the required procedures.

The messages reportedly stated that the lines had been suspended because of incomplete data and asked customers to visit a branch to verify and update their information to restore service.

Sources familiar with the matter told Masrawy that the initial campaign targeted around 19 million SIM cards belonging to the four mobile operators in Egypt, out of approximately 127 million mobile lines in the Egyptian market.

That figure is difficult to digest.

Nineteen million SIM cards were reportedly included in the initial verification campaign — in a market with around 127 million registered mobile lines.

And this is why I cannot simply look at the whole affair as a technical problem or an administrative mess.

The government may have initially viewed it as a problem of incomplete or inaccurate subscriber data. But the implications go much further.

If personal data can be used to register mobile lines without people’s knowledge, those lines can be used for illegal activities while pointing back to innocent people.

That is the national-security concern for me.

Days after the scandal broke, a foul and taamiya restaurant owner went on TikTok and Facebook to report that he had bought paper by the kilo to use as wrapping for traditional sandwiches, only to discover that the papers were apparently original Orange Egypt mobile phone contracts!!

As of now, I have not seen any comment from Orange Egypt or the NTRA, including a denial of the video’s claims.

Now, who really did this?

The alt-right anti-refugee nationalists are claiming, as usual, that refugees from Sudan were behind it, allegedly in cooperation with a mafia operating inside the mobile phone companies.

Others have suggested a much more mundane explanation: sales and customer-service employees registering extra lines to meet monthly sales targets and increase their numbers.

The case of Amr, the Zagazig University student, lends some weight to this theory. According to his family, he was told by a friend that he was helping the friend’s relative, who allegedly worked as a telecom sales representative, meet a sales target.

But then came the Ministry of Interior.

In the weeks following the outbreak of the scandal, the ministry announced that Cairo Security Directorate investigators had arrested two people accused of selling mobile phone lines activated using other people’s data without proof that the users actually owned them.

On 25 August, security authorities announced the arrest of 18 people — six customer-service employees at a telecommunications company and 12 employees of intermediary companies and mobile-line dealers — after investigations into reports of mobile lines being registered in customers’ names without their knowledge. Investigators found that customer details had been used to register lines without customers being present or their signatures being verified, while intermediary companies had diverted lines to dealers and accepted identity-card copies to meet sales targets — a practice that had continued for several years.

Authorities seized 4,071 mobile lines, most already activated and linked to electronic wallets, along with phones, contracts, copies of national ID cards and storage devices containing customer data. The suspects reportedly admitted to the offences.

Personally, considering the scale of what was uncovered across the four mobile operators, I find it difficult to see this simply as a handful of greedy sales representatives chasing monthly targets.

We are not talking only about mobile phone lines. We are also talking about mobile money wallets capable of transferring thousands — potentially hundreds of thousands — of Egyptian pounds over months or years.

That raises a much bigger question about what these lines and wallets may have been used for.

And that is where the national-security dimension comes in.

The NTRA eventually referred Egypt’s four mobile operators to the Public Prosecution over violations involving SIM lines registered under customers’ names without their knowledge. At the same time, it ordered emergency measures requiring operators to re-verify the identities of actual line holders.

The new measures included stopping the activation of new corporate-registered lines, requiring existing corporate-line users to sign new contracts in their own names, and cancelling lines whose paperwork was not completed. The NTRA also ordered operators to accelerate biometric verification through their mobile applications and warned that companies violating the rules could face legal and administrative sanctions, including suspension of their ability to sell or activate new lines.

This is the bare minimum, if you think about it.

What Egyptian citizens really need is transparency: a serious investigation into how this happened, how personal data was obtained and used, how many lines and wallets were affected, and whether any of them were subsequently used in criminal activity.

This is not simply a telecom customer-service problem.

It involves the CEOs of the four mobile operators, the NTRA, the Ministry of Communications and Information Technology and, ultimately, the Egyptian state’s entire system for protecting citizens’ identities and personal data.

And now we are being asked to trust the same system with our biometric data.

That brings me back to my original question: how, or why, should I trust mobile operators and the NTRA with my facial biometrics when my National ID data could apparently be used to register mobile lines without my knowledge in the first place?

And another question remains unanswered: how were those National ID details obtained, and what exactly were they used for?

The NTRA has also made clear that it has held each telecom company responsible for its customers’ lines since 2018.

Why 2018?

That year marked a major tightening of Egypt’s regulation of mobile-line registration. Egypt enacted the Anti-Cyber and Information Technology Crimes Law, No. 175 of 2018, while the NTRA also introduced stricter measures to combat unidentified mobile lines, restrict sales and activation to authorised channels, and strengthen the verification of subscriber data.

In other words, the safeguards were supposed to have been there.

For years, Egyptians have also heard about alleged breaches of databases containing personal information being offered for sale online. It is one possible explanation for why so many of us are bombarded with unsolicited calls and messages from property developers and other businesses — although the source of any particular data leak cannot simply be assumed.

But this is precisely why I believe the question needs to be asked.

How did this happen?

And how long had it been happening?

The four operators — Orange, Vodafone and e& Egypt, alongside WE — should be conducting serious internal investigations into what happened within their Egyptian operations. I would assume that some form of investigation is already taking place, because that is the least any company would do when an incident potentially affects its customers, reputation and shareholders.

And imagine for a moment if something on this scale had happened in the EU or the United States.

There would be questions.

Lots of questions.

Unfortunately, we are in Egypt.

And denial is a river here, after all.

No comments:

Post a Comment

Thank You for your comment
Please keep it civilized here, racist and hateful comments are not accepted
The Comments in this blog with exclusion of the blog's owner does not represent the views of the blog's owner.