South Korea has announced a new policy requiring facial recognition scans for individuals registering new mobile phone numbers, aiming to curb the widespread use of stolen identities in telecom-related scams. The Ministry of Science and ICT stated that the initiative, which will be implemented by the country's three major mobile carriers and mobile virtual network operators, is designed to prevent criminals from using stolen or fabricated IDs to activate SIM cards. The new requirement will compare the photo on an official identification card with a real-time facial scan, making it significantly harder to register devices under false names. This measure follows a series of high-profile data breaches and a surge in voice phishing scams, with over 21,000 cases reported in 2025 alone.
The policy is set to take effect on March 23, following a pilot phase, and will leverage existing digital credential apps such as “PASS” to store and verify biometric data. Recent incidents, including the massive data breach at SK Telecom that exposed SIM card data of nearly 27 million subscribers, have highlighted the vulnerabilities in South Korea’s telecom sector. Authorities have responded with stricter penalties for carriers failing to prevent scams and have imposed significant fines for poor security practices, such as storing credentials in plaintext and lacking basic access controls. The government hopes that the new facial recognition requirement will restore trust and reduce the risk of identity-based telecom fraud.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
The government said the new facial recognition requirement will take effect on March 23. The measure will add biometric verification to existing identity checks, including use of the PASS digital credential app.
On December 22, 2025, the Ministry of Science and ICT announced that new mobile number and SIM registrations will require facial recognition verification. The rule applies to the three major carriers and MVNOs and is intended to reduce identity theft, illegal registrations, and voice phishing.
South Korean authorities found that mobile virtual network operators accounted for 92% of counterfeit phone registrations detected in 2024. The finding highlighted systemic weaknesses in identity verification for new mobile accounts.
Before the nationwide mandate, South Korea ran a pilot program for facial recognition checks during new mobile phone registrations. The pilot informed the later decision to expand the requirement to major carriers and MVNOs.
In April 2025, SK Telecom suffered a major breach in which SIM card-related data for nearly 27 million subscribers was stolen. Reports said the incident was linked to poor access controls and later drew regulatory criticism and penalties.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.