Singapore has required buyers to verify their identity with a government-issued ID when registering a SIM card since 2005. This is the type of safeguard the US Federal Communications Commission is now considering for American mobile users.
Yet identity verification has not eliminated telecom-enabled fraud. Singaporeans lost S$913.1 million to scams in 2025, according to the Singapore Police Force’s Annual Scam and Cybercrime Brief 2025, with scams exceeding all other crime categories in the country combined.
Singapore’s experience offers a reality check for those who see the FCC’s proposal as a standalone solution to America’s robocall and fraud problem. Verified identities can strengthen accountability, but they cannot prevent scams without broader enforcement, technical controls, and consumer protections.
Inside the FCC’s SIM Verification Proposal
The FCC’s Further Notice of Proposed Rulemaking, adopted on April 30 and known as FCC 26-27, would require US telecom providers to request several identifying pieces of information before activating or renewing phone service, including prepaid plans.
While it doesn’t intend to ban anonymous burner phones, it would make activating one without leaving an identity trail practically impossible. The commission’s stated goal is to stop illegal calls from originating on US networks and to make it harder for scam and robocall operators to hide behind anonymous numbers, particularly those routed through SIM boxes.
Privacy groups have pushed back hard. The Electronic Frontier Foundation and the ACLU jointly told the FCC that blanket verification would strip away a channel that is legitimately used by several law-abiding Americans. It also means telcos would store more sensitive personal data than they do now.
Singapore already answered the first question; the hard part came next
For Singapore, that debate over anonymity versus verification is old news. IMDA’s mandatory registration regime, which requires buyers to present an NRIC, passport, or work pass before a SIM is activated, was designed to fix exactly the problem the FCC is now worried about. It’s tighter, too — prepaid SIMs bought on a passport now lapse after 30 days unless the holder re-registers with a Singapore-issued ID.
What Singapore’s experience shows is that identity checks at the point of purchase solve one problem and immediately create another.
Scam and cybercrime cases actually fell 24.8% in 2025 to 41,974, and losses dropped 19% year-on-year. These are genuine progress. But one category moved sharply in the other direction: government-official impersonation scams, which nearly tripled in the first half of 2025 alone.
Police traced part of that surge to a cross-border syndicate whose GSM gateway devices, seized across jurisdictions, routed overseas calls through Singapore’s own mobile networks, making them appear to originate locally. Registration didn’t stop that; the numbers being spoofed and abused were often already legitimately registered, just rented, resold, or hijacked further down the chain.
That’s the gap the FCC proposal doesn’t obviously close, and one Singapore’s regulators have had to address separately.
Rather than doubling down on identity checks at activation, Singapore’s newer defences target what happens to a line after it’s issued. The Facility Restriction Framework, rolled out in October 2025 with the Monetary Authority of Singapore, IMDA, and GovTech, has already placed 801 telco lines under restriction as suspected SIM mules — registered numbers that get sold on or rented out to scam operations rather than used by anonymous first-time buyers.
Combined with other controls that let authorities compel platforms to act on scam content, the strategy has shifted from “know who bought the SIM” to “watch what the SIM is doing now.”
The privacy trade-off Singapore is still working through
Singapore’s own regulators have also grown more wary of relying on identity documents as a security control. In June 2025, the Personal Data Protection Commission (PDPC) and the Cyber Security Agency jointly warned organisations against using NRIC numbers to authenticate people. This draws a line between merely identifying someone and actually authenticating them, since an NRIC number can’t be assumed to be secret and may already be known to a scammer.
Private organisations, including telcos, have until the end of 2026 to phase out NRIC-based authentication or face enforcement action by the PDPC.
The irony is hard to miss. Singapore is simultaneously the model the FCC’s proposal resembles and a live case study in why identity documents make imperfect security credentials once scammers learn to work around, rather than through, them.
What this means going forward
For IT and security leaders in Singapore watching the FCC debate, the practical takeaway isn’t that verification is pointless. Case numbers falling 24.8% argues otherwise. It’s that identity checks at activation are a floor, not a ceiling.
Enterprises relying on caller ID or registered numbers as a trust signal should treat that signal as necessary but not sufficient, especially as impersonation scams continue to climb.
The FCC’s comment period on the proposal remains open, with a final vote yet to be scheduled. Singapore’s own transition away from NRIC-based authentication runs through December 2026. Both timelines are worth watching together: one is testing whether verification is worth adopting, the other is testing what happens once you’ve had it for twenty years.