Indonesia Surpasses 10 Million Biometric SIM Card Registrations: Ministry Targets 10 Million More to Combat Cybercrime and Identity Theft
JAKARTA — In a major step toward securing the nation’s digital ecosystem, the Indonesian Ministry of Communication and Digital Affairs (Kementerian Komunikasi dan Digital, or Komdigi) announced that biometric-based SIM card registrations had officially surpassed the 10 million mark as of July 22, 2026.
The milestone marks a transition in how Indonesia manages telecommunications security. It represents a shift from traditional, text-based registration methods to a secure identity verification system designed to eradicate identity theft, digital fraud, and the proliferation of illegal SIM cards.
Speaking at the "Declaration of Joint Commitment for the Full Implementation of Biometric Data-Based Customer Registration" in Jakarta, the Minister of Communication and Digital Affairs, Meutya Hafid, emphasized that this milestone is part of a broader government effort to protect citizens from escalating digital threats.
With the 10 million milestone achieved, the government has set an ambitious target for mobile network operators (MNOs) to register or re-verify an additional 10 million subscribers using biometric data within the next month.
Main Facts: The Transition to Biometric-Based Telecom Security
The implementation of biometric SIM card registration is governed by the Minister of Communication and Digital Regulation (Peraturan Menteri Komunikasi dan Digital) No. 7 of 2026. This regulation mandates that all cellular telecommunications providers adopt strict "Know Your Customer" (KYC) protocols using biometric verification, such as facial recognition or fingerprint scanning, linked directly to the national civil registry database.
The core objectives of this policy include:
- Preventing Identity Theft: By requiring physical biometric verification, the system prevents unauthorized individuals from registering SIM cards using stolen National Identification Numbers (NIK) and Family Card (KK) details.
- Combating Cybercrime: The government aims to curb digital crimes, including online gambling, SMS spam, phishing, financial fraud, and online extortion, which often rely on anonymous or falsely registered SIM cards.
- Enforcing Operator Accountability: Mobile operators are legally required to verify the identity of every subscriber, with strict penalties for non-compliance.
- Protecting Data Privacy: To mitigate the risk of data breaches, the Ministry has prohibited telecommunications operators from storing raw biometric data on their private servers. Instead, they must perform real-time verification against the central government database.
Chronology: The Evolution of SIM Card Registration in Indonesia
To understand the significance of the 10 million milestone in July 2026, it is essential to trace the policy’s development over the past decade:
1. The Pre-Biometric Era (Prior to 2018)
For years, purchasing and activating a prepaid SIM card in Indonesia required minimal verification. This lax system allowed individuals to purchase pre-activated "burner" SIM cards at roadside kiosks, creating an environment highly susceptible to spam, SMS-based banking fraud, and criminal coordination.
2. The NIK and KK Text-Based Mandate (2018–2025)
In 2018, the government introduced a mandatory registration system requiring users to link their SIM cards to their NIK and KK numbers via SMS. While this significantly reduced anonymity, severe loopholes emerged. Bad actors exploited leaked national identity databases to register thousands of SIM cards under stolen identities, bypassing the spirit of the regulation.
3. The Introduction of Ministerial Regulation No. 7 of 2026
Recognizing the limitations of text-based registration, the Ministry drafted and enacted Regulation No. 7 of 2026. This policy officially introduced biometric verification as the standard for mobile customer registration, establishing a secure validation process with the Ministry of Home Affairs’ Directorate General of Population and Civil Registration (Dukcapil).
4. Rapid Scale-Up and the 10 Million Milestone (Mid-2026)
Following the enactment of the regulation, mobile network operators upgraded their digital infrastructure, retail outlets, and mobile applications to support biometric scanning. By early July 2026, the number of biometrically registered users reached 6.8 million.
By July 22, 2026, this figure surged past 10 million, culminating in the joint declaration in Jakarta where Minister Meutya Hafid announced the next phase of the nationwide rollout.
Supporting Data: Key Metrics and Technical Realities
The transition to a biometric registration framework is supported by data demonstrating both the speed of adoption and the technical feasibility of the system.
+-------------------------------------------------------------+
| BIOMETRIC SIM REGISTRATION METRICS |
+-------------------------------------------------------------+
| Milestone (as of July 22, 2026) | 10 Million Users |
+-------------------------------------------------------------+
| Success Rate of Biometric Verification | 83% |
+-------------------------------------------------------------+
| Target for Next 30 Days | +10 Million Users |
+-------------------------------------------------------------+
| Primary Verification Method | Facial Recognition |
+-------------------------------------------------------------+
| Regulatory Framework | Permen Komdigi No. 7|
+-------------------------------------------------------------+
The 83% Success Rate
Initial reports from pilot programs and early rollouts indicated that the biometric registration process achieved an 83% success rate. The remaining 17% of failed attempts were largely attributed to technical factors, such as:
- Poor lighting during facial scans.
- Low-resolution front-facing cameras on older smartphone models.
- Discrepancies between physical appearances and older photos stored in the national electronic ID card (e-KTP) database.
The Ministry and telecommunications companies are actively working to resolve these technical issues by updating application software and providing physical biometric scanners at operator service centers.
The Next 10 Million: New vs. Legacy Users
To meet the target of adding 10 million biometrically verified users within the next month, the government is not relying solely on new mobile subscribers. The strategy also targets legacy subscribers who have not yet undergone biometric verification.
Users with older, text-registered SIM cards will be encouraged or required to complete biometric verification through operator apps or physical outlets to maintain their services.
Official Responses: Government Directives and Operator Compliance
The announcement of the 10 million milestone was accompanied by clear directives from the government to the country’s major telecommunications providers, including Telkomsel, Indosat Ooredoo Hutchison, XL Axiata, and Smartfren.
Minister Meutya Hafid on Inclusivity and Ease of Use
Minister Meutya Hafid emphasized that while security is paramount, the process must not alienate or inconvenience the public.
"This is one of the ways the state is present to secure and provide safety services for our citizens, particularly cellular operator users. However, the goal is to protect mobile users, not to complicate or make their lives difficult. I ask that the systems and technologies utilized remain easy to use and inclusive for everyone."
The Minister stressed that operators must ensure their digital applications are accessible to all demographics, including the elderly, individuals with physical disabilities, and those living in remote areas with limited internet connectivity.
Strict Prohibition on Local Biometric Data Storage
Addressing data privacy concerns, the Ministry of Communication and Digital Affairs confirmed that telecommunications operators are strictly prohibited from saving, storing, or archiving subscribers’ raw biometric data.
During the registration process, the operator’s application captures the biometric scan (e.g., a selfie) and securely transmits it to the Dukcapil national database for real-time verification. Once verified, the raw biometric image is discarded by the operator, ensuring that a security breach of an operator’s servers will not compromise citizens’ sensitive biometric profiles.
Sanctions for Non-Compliant Operators
Komdigi has warned that cellular operators failing to comply with the biometric KYC standards laid out in Regulation No. 7 of 2026 will face administrative sanctions. These penalties range from formal warnings and heavy fines to the suspension of operational licenses for repeated or systemic non-compliance.
Implications for National Security and the Digital Economy
The shift toward biometric-based mobile registration has far-reaching implications for Indonesia’s national security, public safety, and digital economy.
1. Curbing Online Gambling and Financial Scams
Indonesia has faced challenges with online gambling and digital financial scams, which often rely on networks of fake SIM cards to communicate with victims and manage illicit payment gateways. By tying every active SIM card to a verified physical identity, law enforcement agencies can track the origin of fraudulent communications, disrupting the operational infrastructure of cybercriminals.
2. Protecting Identity Integrity
In the past, thousands of citizens discovered that their NIK had been used without their consent to register dozens of unauthorized SIM cards. Biometric verification empowers citizens by ensuring that their identity cannot be exploited. Under the new system, any attempt to register a SIM card using another person’s NIK will fail during the facial verification phase.
3. Boosting Trust in the Digital Economy
As Indonesia’s digital economy grows, secure telecommunications infrastructure is vital for mobile banking, e-commerce, and digital payments. Stronger KYC protocols at the telecom level enhance the security of One-Time Passwords (OTPs) sent via SMS, reducing the risk of account takeovers and boosting overall consumer trust in digital financial services.
4. Overcoming the Digital Divide
While the policy offers clear security benefits, its implementation faces logistical challenges in rural and underdeveloped regions (the 3T areas: tertinggal, terdepan, dan terluar). Ensuring that residents in these areas have access to the necessary devices, high-speed connectivity, and physical registration kiosks remains an ongoing challenge for both the government and network operators.
As Indonesia enters the next phase of this security initiative, the success of the biometric SIM card registration program will depend on balancing security enforcement with technological accessibility and data privacy.
