|
Reading time: 23 min

Why Mexico's SIM Card Registry Is Failing — and Will Keep Failing


Summary: Mexico’s mandatory mobile SIM registration is not a bad idea in principle — it is an idea with an execution timeline that was impossible from the start. Peru took nearly 1,000 days just to launch its biometric system and is still fixing it nine years later; Brazil rolled out its scheme in phases across two decades of legal framework. Germany, which does have a functioning prepaid SIM identification system, did not make that leap overnight: the obligation was embedded in its Telecommunications Act as part of an anti-terrorism package, with eighteen months allotted just to retroactively verify already-active lines, and backed by a civil identification infrastructure that had been maturing for decades. It is an unequal comparison: Germany did not solve this in months — it built the solution on a state that had already solved nearly everything else. Mexico tried to compress an equivalent process into six months without that foundation. Seven months after launch, the results are measurable: a data breach on day two of operation, a cost of over 4 billion pesos distributed unevenly between large and small carriers, a schedule the regulator itself had to rewrite on an emergency basis without public consultation, and a black market of pre-registered SIM cards that continues to reproduce the very anonymity the law claimed to eliminate. None of this means that linking a phone line to an identity is inherently impossible — the very countries Mexico cites as models achieved it. What these seven months demonstrate is that the Mexican design, compressed into a fraction of the time it took any comparable country, was not built to sustain the objective it set for itself.

When the Telecommunications Regulatory Commission (CRT) unveiled the Lineamientos para la Identificación de Líneas Telefónicas Móviles in December 2025, its stated goal was to eliminate the anonymity that, according to the regulator itself, enables crimes such as extortion and phone fraud. It is a goal other countries have managed to achieve through similar schemes. The problem is not the underlying idea but the way Mexico chose to execute it. Seven months after launch, with the original deadline expired and replaced on an emergency basis by a phased schedule running through the end of 2026, the evidence shows a pattern: the registry was implemented in a fraction of the time comparable schemes took elsewhere, imposed disproportionate costs on smaller carriers, exposed sensitive data belonging to millions of users on day two of operation, and coexists with a parallel market that replicates the anonymity it claimed to combat.

1. Regulatory Framework and Linking Mechanism

On December 8, 2025, the CRT’s full Board unanimously approved Agreement P/CRT/EXT/08122025/144, published the following day in the Diario Oficial de la Federación (Official Gazette). From January 9, 2026 onward, every mobile line — including prepaid lines, previously anonymous — had to be linked to an identifiable account holder. The CRT did not act on its own initiative: Article Thirty of the Transitional Provisions of the Ley en Materia de Telecomunicaciones y Radiodifusión, published July 16, 2025, gave it 120 business days to issue the guidelines — a constraint that helps explain, though does not by itself justify, the urgency of the rest of the process.

The mechanism requires, for natural persons, a valid government-issued ID plus the national identity code (CURP); for legal entities, a tax ID (RFC) plus accreditation of the legal representative; for foreign nationals, a passport or temporary CURP. The process can be completed in person or remotely; both require a “Liveness Test” (Prueba de Vida) to confirm that the applicant matches the ID holder. The Agreement’s stated objective is to “reduce the spaces for illicit use of mobile communications technologies” (Articles 103 and 164, Section III of the Law).

The CRT frames the measure as part of a regional trend, citing eight countries as precedent:

CountryAuthority / StandardYearKey Feature
ArgentinaENACOM2023Multi-step validation + biometrics
BrazilANATEL2021Photo + document prior to activation
ChileSUBTEL2021Name, address, IMEI/MSISDN/IMSI
ColombiaCRC, Res. 50502016Real-time document verification
Costa RicaSUTELName, national ID, address, email
EcuadorCONATEL2009Cross-check against civil registry
PeruOSIPTEL2017Fingerprint linked to RENIEC

Of these, at least two (Argentina and Peru) incorporate biometric verification — an element the Mexican Guidelines explicitly rule out on paper: Article 34 of the Sole Annex prohibits storing “any biometric data, photograph, or copy of an official ID,” and Article 44 reiterates this as an absolute prohibition. The gap between that prohibition and the actual practice of carriers is documented further below. The Agreement also records a Public Consultation process (October 30 to November 27, 2025, 36 submissions) whose final outcome “changed significantly from its draft,” without specifying how, and a pilot test conducted since September 1, 2025.

2. Six Months Where Others Took Years

In Mexico, the gap between the enabling legislation (July 16, 2025) and the registry’s entry into force (January 9, 2026) was less than six months; the original public compliance window, from January 9 to June 30, was practically exactly six months. None of the countries cited as precedent followed a comparable timeline:

  • Peru launched its biometric system in 2017. By 2019, nearly 1,000 days into implementation, it was still generating operator fines. Nine years later, in 2026, RENIEC announced it was replacing the system with a facial-verification scheme after detecting irregular use of biometric queries.
  • Brazil rolled out its recadastramento in phases over several years (2019, 2020, 2021), built on a legal framework dating to 2003 and an ANATEL resolution from 2007. From the original framework to full digital implementation, more than fifteen years elapsed.
  • Argentina ordered its registration in 2016; two years later, 40% of San Juan’s prepaid lines were still unregistered, with successive deadline extensions.

The technical consequence of Mexico’s compressed timeline was documented within the industry itself: Movistar had to “accelerate the implementation of registration platforms and reinforce its cybersecurity systems in just 30 days” — the same transitional window the Agreement grants carriers to activate their Management Platforms, a margin strikingly short for securing a system that processes sensitive data belonging to tens of millions of people.

3. The Cost to Operators, Distributed Without Neutrality

Implementation was not free: estimates cited across multiple outlets put the combined investment at over 4 billion pesos for Telcel, AT&T, Movistar, and Altán Redes — a figure that Mony De Swaan Addati (former president of the now-dissolved Cofetel, today president of the Mexican Association of Mobile Virtual Operators) confirmed as the cost of platforms, querying, and secure storage for the country’s approximately 160 million lines. The CRT itself reported an additional 22 million pesos for its central platform alone.

That cost was not distributed evenly. A UBS Investment Bank study circulated in October 2025 warned that Telcel held structural advantages over its competitors: “software and commercial requirements… could be costly for operators with a smaller customer base, such as AT&T, Movistar, and BAIT.” The Bait case illustrates the problem: much of its growth had depended on free SIM cards distributed at Walmart stores, many discarded by users — a low-commitment model structurally incompatible with a process now requiring identity verification line by line. UBS anticipated this “could generate additional churn” precisely among the smaller operators.

That inherent advantage, however, did not translate into speed: the breakdown the CRT published on April 20, 2026 showed Telcel — which holds more than half the market — at only 19% progress, behind AT&T (29%) and Bait (28%). Telcel’s advantage appears to have been resilience against cost, not execution speed. At the operational level, the asymmetry repeated itself: carriers with proprietary networks built their platforms under their own control, while MVNOs depend on wholesalers and pay 3.45 pesos per linking attempt on Altán Redes’ infrastructure — successful or not — a variable cost that disproportionately penalizes smaller operators. De Swaan summarized the industry’s frustration in a line that El Financiero ran as its headline:

“I would throw the registry in the trash — as currently designed, I would not continue with it”

— Mony De Swaan Addati, El Financiero

The impact was measurable: operators lost over one million prepaid subscribers in the first quarter of 2026, and postpaid growth slowed across all four major carriers.

Bridging the budget and the technical failure. Two empirical data points documented in this piece describe the pressure on the software development cycle: the Third Transitional Article of the original Agreement required carriers to activate their Management Platforms in just 30 calendar days — a window Xataka México documented as insufficient even from Movistar’s own perspective — and the industry faced combined costs exceeding 4 billion pesos, a large share absorbed by logistical fees such as the 3.45-peso-per-attempt charge on Altán Redes’ network rather than by reinforcing security architecture, as suggested by the industry’s own complaints reported by El Financiero in May 2026.

Methodological note: Neither of the above sources — neither Telcel nor the CRT — explicitly states that this combination of timeline and cost caused the access-control failure documented below. That link is not confirmed as fact and should not be read as such.

It is, however, a reading consistent with industry standards on how a development cycle behaves under time compression. The OWASP API Security Top 10 (2023 edition) ranks Broken Object Level Authorization (BOLA, also known as IDOR) first among API security risks, estimating that this class of flaw accounts for roughly 40% of documented API attacks; the framework itself notes that object-level authorization controls are difficult to implement correctly and require exhaustive testing on every endpoint that receives a user-supplied identifier — precisely the kind of testing that a 30-day cycle leaves little room to complete. The NIST Secure Software Development Framework (SP 800-218) makes the same point from another angle: its practices PO.1 (define security requirements before development) and PW.2 (verify the design meets those requirements) assume that security must be integrated from the start of the software lifecycle, not added afterward — something structurally harder to sustain when the delivery date is set by an external authority as a regulatory mandate with no room for negotiation.

Within that frame of reference, the reasonable reading — unconfirmed but consistent with application security literature — is that a 30-day window to put into production a system processing the identity and CURP of millions of people leaves statistically little room for the kind of authorization review that BOLA demands, and that a budget oriented first toward meeting interconnection quotas and the regulatory calendar, ahead of auditing every endpoint, is exactly the pattern that DevSecOps literature describes as compliance-driven technical debt: the deadline is regulatory and inflexible, so development prioritizes making the system work — accepting and processing registrations — over ensuring it is properly protected. Telcel’s portal satisfied the first condition and failed the second.

4. A Design Promise the Practice Couldn’t Keep

The absence of biometrics in the regulatory design is explained, almost certainly, by a lesson learned from a recent failure. In 2021, the Padrón Nacional de Usuarios de Telefonía Móvil (PANAUT) was created — a registry that did require biometrics. The Supreme Court declared it unconstitutional in resolving Constitutional Challenge 82/2021. Although the consensus of the draft was outlined in the session of April 25, 2022, the final vote on the effects and rulings was consolidated in the session of April 26, 2022, by a majority of 9 to 2 (with Justice Ana Margarita Ríos Farjat and Justice Alberto Pérez Dayán dissenting from the total invalidation of the decree), reaching the necessary qualified majority to invalidate the entire decree after concluding that the measure did not pass a proportionality test against the right to privacy and did not guarantee it would reduce the crimes it claimed to address. Before that, there had been another attempt — the RENAUT of 2009 — whose database ended up being sold illegally online. In January 2026, the idea spread widely on social media that the new registry was the same invalidated PANAUT; fact-checkers such as El Heraldo de México classified that equivalence as false, but the force of the confusion (one post exceeded 23,000 reactions on Facebook) reveals a distrust built on two precedents that failed for different reasons.

That distrust found immediate concrete technical support, on a timeline consistent with what the preceding framework would anticipate. On January 10, 2026, at 12:06 PM — barely 24 hours after the registry took effect — cybersecurity journalist Ignacio Gómez Villaseñor published direct evidence of the flaw on his X account: a screenshot of browser developer tools showing that entering any Telcel phone number on the registration portal caused the backend to return a complete JSON object (name, CURP, email, nationality) before the user had entered the SMS verification code.

Foto de perfil de Ignacio Gómez Villaseñor

📵 | GRAVÍSIMO: Telcel expone datos personales de TODOS sus clientes en el nuevo registro obligatorio El portal oficial de @Telcel (registro.telcel) presenta una vulnerabilidad seguridad crítica que deja al descubierto la identidad, la CURP, el RFC y correo electrónico de millones de usuarios. Esto ocurre solo 24 horas después de haber entrado en vigor la normativa que obliga a registrar todas las líneas móviles en el país. Al ingresar cualquier número telefónico de Telcel en el formulario, el sistema interno devuelve —sin necesidad de contraseñas ni códigos de verificación— un paquete de información completo del titular de la línea. Esto es sumamente peligroso. Cualquier ciberdelincuente podría usar alguna de las bases de números de Telcel y automatizar la extracción masiva de información.

Captura de pantalla de evidencia adjunta al tweet

The tweet, with over 1.5 million views, shows the screen still prompting for the verification code while the Network panel already displays the account holder’s data. It is technical evidence that the on-screen validation was cosmetic: the sensitive data had already traveled to the client before any real verification was completed.

An analysis by Quantum Secure Labs characterized the pattern as “consistent with access-control vulnerabilities (e.g., IDOR)” or with public endpoints lacking permission checks — the same category, BOLA/IDOR, that OWASP ranks first. It is worth explaining what that classification implies. An IDOR (Insecure Direct Object Reference) occurs when the backend exposes a direct reference to an internal record — in this case, a citizen’s file — through a predictable parameter in the request (the phone number), without validating whether the requester is authorized to view that particular object. It works because the API was designed to return the data payload before verifying the SMS code: the frontend visually hid the information from the user, but the network traffic traveling between the browser and the server already contained the complete sensitive data — something anyone with open developer tools, as Villaseñor did, could see directly. The real risk of such a flaw is not a curious user glancing at their own browser traffic, but automation: an attacker does not need to interact with the graphical interface at all — they can write a script that iterates requests against the API, traversing the full national telephone numbering space, mass-extracting data on millions of people without ever authenticating. Xataka México reported exactly that possibility: that the flaw could enable automated queries against already-leaked number databases.

The exposure of CURP and RFC alongside a phone number is not an abstract risk: it is precisely the information an attacker needs to carry out SIM swapping — the fraud in which someone impersonates an account holder to the carrier, gets the number transferred to a SIM under their control, and then intercepts the two-factor authentication codes (2FA) that banks and other platforms send via SMS. With the number hijacked, the attacker can access bank accounts, email inboxes, and corporate profiles that rely on that same number as a second factor. It is, in other words, the scenario opposite to the one the registry claimed to prevent: rather than making identity fraud harder, the flaw on day one made it measurably easier.

Telcel, through its Communications Subdirector Renato Flores, acknowledged “a technical vulnerability” but denied a mass breach, attributing it to system overload, and took the portal offline for two hours. Villaseñor documented on video that no code was required to view the data, contradicting that account. After the flaw became public, the system began returning null values for sensitive fields — indicating the fix came after the exposure, not before. The Secretariat for Anti-Corruption and Good Governance opened 20 investigation files; the CRT limited its response to attributing the incident to high user volume.

The problem did not end there. On April 27, 2026, the same journalist documented that cybercrime forums were already selling complete impersonation packages (selfie, ID, and “liveness test” video) specifically designed to bypass the verification filters used in phone registration — built with data stolen since 2024, that is, before the registry even existed.

Foto de perfil de Ignacio Gómez Villaseñor

🔴 | FILTRAN PAQUETES PARA SUPLANTAR A MEXICANOS EN REGISTROS CON "PRUEBA DE VIDA" En foros de ciberdelincuencia ya se venden paquetes completos (selfie, identificación y video selfie de cada persona) para pasar filtros KYC. Sí, muy similares a los que se usan en el registro telefónico. Los paquetes que muestro en este video apenas se publicaron ayer, aunque todo indica que la información fue robada in 2024. Aun así, las credenciales de elector siguen vigentes (y es poco probable que estas personas hayan cambiado significativamente en dos años). Esto no es teórico: estoy MOSTRANDO EVIDENCIA de que no existe seguridad para un registro de esta magnitud. Y no solo eso, ya hay antecedentes de fallas en el resguardo de datos, como en el caso de @Telcel Esto ya está ocurriendo. El gobierno debe reconsideraer: si quieren, no nos den la razón; inventen lo que quieran, pero ese registro es una muy mala idea. Las pruebas están aquí (y en cientos o miles de hackeos que estamos sufriendo todos los días).

And on March 18, 2026, with the official progress still below 10% by his own count — a figure lower than what the CRT reported for similar dates; it is worth noting that Villaseñor maintains an active public stance against the registry — the journalist also denounced organized campaigns aimed at discrediting the specialists who had been pointing out these flaws.

Foto de perfil de Ignacio Gómez Villaseñor

📵 | PREOCUPA AL GOBIERNO FRACASO DEL REGISTRO DE CELULARES La información que advertí sobre la exposición masiva de datos en @Telcel al arrancar el periodo del registro obligatorio de líneas ocasionó demasiada desconfianza en los mexicanos. El porcentaje de líneas registradas es mínimo (ni 10%) y, pese a todo pronóstico, la voz de los mexicanos se está haciendo presente: es totalmente inviable que las compañías cancelen los números no asociados con CURP. ¡Se quedarían sin clientes! El tema ha escalado hasta el punto en el que analizan campañas para tratar de deslegitimar la preocupación real de especialistas en la materia que han insistido en que la medida no sirve de absolutamente nada (y hay evidencia de sobra). ¿Qué habría pasado si la @CRTGobMX y @Telcel no hubieran insistido en mentir? Yo insisto: no se registren. Le estamos ganando al mismo gobierno.

Captura de pantalla de evidencia adjunta al tweet

Both the original press release and the Guidelines invoke the Ley Federal de Protección de Datos Personales (Federal Data Protection Law) as a safeguard; no reviewed source documents a sanction applied to Telcel under that law. Even the GSM Association, the international mobile operator consortium, noted that there is no evidence that this type of registry has any real impact on reducing the crimes it claims to address.

The gap between policy and practice recurs with biometrics. The Guidelines prohibit storing biometric data, but do not prohibit capturing it momentarily for matching — which is precisely what the Liveness Test does. In actual implementation, that distinction dissolved: Bait requires photographing the ID and moving one’s head in front of the camera; Telcel requests a selfie; AT&T and Movistar may request equivalent elements, according to Xataka México. The official justification is that it involves an ephemeral algorithmic comparison that is not stored, but the same source reports that, according to specialists and the ruling of a federal court, active doubt exists as to whether carriers actually honor that commitment. According to an investigation by El Sabueso, the only way to avoid submitting biometrics is to appear in person — an alternative that depends on the user being able to physically travel to a store, a condition no official communication mentions.

5. The Numbers That Confirm the Timeline’s Failure

Official Progress of Mexico's Mobile Line Registration (2026)

Official Progress of Mexico's Mobile Line Registration (2026) - Tabla de Datos de Respaldo (Percentage of lines registered)
Fecha / PuntoPercentage of lines registered
Jan 231.9%
Apr 117.33%
Apr 2019.1%
May 1934%
Jun 539%
Jun 2241.52%

The reported total universe varied between 144 and 160 million lines depending on the date and source, without consistent explanation. On April 1, with 17.33% progress, the CRT confirmed there would be no extension. On April 20, it broke down progress by carrier (Bait 28%, AT&T 29%, Movistar 16%, Telcel 19%), with the market dominant among the lowest-performing. At every press conference the CRT repeated that the government would not have access to the data and that biometrics would not be required — a formula that does not hold without significant qualification given what is documented above. The CIU rated the pace as “insufficient” and noted that the mandatory requirement “increases the cost of access and discourages activation of new lines, especially among lower-income users.”

6. The Last-Minute Amendment

On June 25, 2026, five days before the deadline, the CRT’s full Board approved Agreement P/CRT/EXT/25062026/084, published on June 30 itself. The Agreement acknowledges the reason directly: simultaneously disabling all unlinked lines would produce a “potential adverse impact on network operability… due to signaling overload on the control plane,” with between 82 and 96 million lines still pending according to the previous day’s figures. To avoid a public consultation, the CRT invoked its own emergency exception clause for situations affecting “the welfare of the population, the functioning of services, or public order” — used here to resolve a problem the Commission itself had created through its original design.

The result was a phased disconnection by the last digit of the phone number, distributed through December 31, 2026:

Last digitDisconnection date
0–1August 15 and 31
2–3September 15 and 30
4–5October 15 and 31
6–7November 15 and 30
8–9December 15 and 31

Although the CRT avoided calling it an extension, the effect was to push the real deadline six months beyond the date it had called non-negotiable just weeks earlier. The same amendment permitted the Liveness Test in in-person mode as well (expanding, not reducing, the biometric scope), opened remote registration to legal entities, eliminated the cap on deregistration attempts, prohibited requiring the full phone number as a prerequisite for deregistration, and added the INM residency card as a valid document for foreign nationals — addressing an omission that R3D had flagged since January.

7. The Market That Proves the Goal Was Not Met

Between January 20 and 23, 2026, several outlets documented almost simultaneously that “ready-to-use” SIM cards were available on Facebook Marketplace, at prices ranging from 20 to 55 pesos (up to 1,000 pesos in packs of ten), mostly from Telcel and Bait, concentrated in Mexico City, State of Mexico, and Puebla. El Universal purchased ten at the Polanco Metro station; when attempting to register them, the system rejected them as already linked to someone else’s identity. Some vendors also offered counterfeit INE credentials.

The phenomenon was not limited to the launch period. On May 29, Xataka México documented the purchase of an “already activated” Movistar SIM for 200 pesos on Eje Central — double the base price — specifically marketed as coming “ready to use without needing an INE, CURP, or biometrics.” On June 17, days before the original deadline, reports emerged that the practice was already operating in semi-formal physical commerce in Guadalajara, with no documents requested.

If the stated goal is to eliminate anonymity, the persistence of this market across the full six months of implementation reproduces exactly the scenario the registry sought to prevent, now routed through an informal intermediary: whoever buys the SIM uses someone else’s identity, with the added risk that the real account holder may be held responsible for whatever use it is put to. Several vendors explicitly advertised their SIM cards as a way to avoid biometrics, suggesting that public perception of the official process as invasive partly fueled this parallel demand.

8. A Design Problem, Not an Impossibility

Each of these elements, taken in isolation, could be read as a correctable failure. Viewed together, they describe something more structural: a scheme built on a timeline no comparable country considered viable, which transferred that urgency as cost and technical risk to the industry and to users, and which, seven months later, coexists with the same commercially traded anonymity it claimed to come and eliminate.

This does not amount to saying that linking phone lines to an identity is, at its core, impossible. Peru, Brazil, and Argentina achieved it — though none attempted it in under two years, and all continued adjusting their systems long after declaring them mandatory. What Mexico compressed into six months, without room to pilot at scale, correct security flaws before exposing them to the public, or give smaller operators time to build capacity without falling behind, is exactly the kind of process that in other countries took years of gradual adjustment. The CRT has responded to each problem documented here with targeted fixes, not a reconsideration of the original timeline — which suggests the pattern will keep repeating itself for as long as the underlying logic remains unchanged: solving in months what elsewhere took years.


9. References

Official Gazette and Primary Regulations

  1. Acuerdo P/CRT/EXT/08122025/144, “Lineamientos para la Identificación de Líneas Telefónicas Móviles”. Publicado en el DOF el 9 de diciembre de 2025. https://www.dof.gob.mx/nota_detalle.php?codigo=5775677&fecha=09%2F12%2F2025
  2. Acuerdo P/CRT/EXT/25062026/084, modificación a los Lineamientos. Publicado en el DOF el 30 de junio de 2026. https://www.dof.gob.mx/nota_detalle.php?codigo=5792297.
  3. Ley en Materia de Telecomunicaciones y Radiodifusión. DOF, 16 de julio de 2025. https://www.dof.gob.mx/nota_detalle.php?codigo=5763167
  4. Boletín Bol.008/2025, CRT, 8 de diciembre de 2025. https://www.gob.mx/crt/prensa/la-crt-aprueba-y-emite-los-lineamientos-para-la-identificacion-de-lineas-telefonicas-moviles

Supreme Court of Justice of the Nation

  1. Acción de Inconstitucionalidad 82/2021 y su acumulada 86/2021 (caso PANAUT). Engrose de la SCJN. https://www2.scjn.gob.mx/juridica/engroses/cerrados/Publico/Proyecto/AI82_2021y86_2021acumuladaPL.pdf
  2. Comunicado de la SCJN sobre la declaratoria de inconstitucionalidad. https://www.internet2.scjn.gob.mx/red2/comunicados/comunicado.asp?id=6857

Market Data and Registration Progress

  1. La Jornada, “Sólo 19 de cada 100 usuarios han registrado su celular: CRT”, 21 abr 2026. https://www.jornada.com.mx/2026/04/21/economia/016n1eco
  2. La Jornada, “No habrá prórroga para el registro de líneas telefónicas: CRT”, 1 abr 2026. https://www.jornada.com.mx/noticia/2026/04/01/economia/no-habra-prorroga-para-el-registro-de-lineas-telefonicas-crt
  3. La Jornada, “Sólo 30.2 millones de líneas… 19.1% del padrón telefónico”, 20 abr 2026. https://www.jornada.com.mx/noticia/2026/04/20/economia/solo-302-millones-de-lineas-de-celulares-se-han-registrado-con-su-compania-inicia-campana-de-vinculacion
  4. El Informador, “¿Cuántos usuarios ya registraron su línea celular?”, 8 jun 2026. https://www.informador.mx/mexico/cuantos-usuarios-ya-registraron-su-linea-celular-en-mexico-crt-actualiza-cifra-20260608-0090.html
  5. Diario de Juárez, “Habilitan portal para identificar líneas asociadas a la CURP”, 22 jun 2026. https://diario.mx/juarez/2026/jun/22/habilitan-portal-para-identificar-lineas-asociadas-a-la-curp-1124003.html
  6. Pulso SLP, cita análisis de The CIU, 24 jun 2026. https://pulsoslp.com.mx/nacional/registro-lineas-celulares-mexico-crt-reporta-avance/2060422
  7. El Universal, “Solo 4 de cada 10 líneas… registro avanza, pero a ritmo insuficiente”. https://www.eluniversal.com.mx/cartera/solo-4-de-cada-10-lineas-de-celular-se-han-vinculado-a-la-curp-registro-avanza-pero-a-ritmo-insuficiente/
  8. El Financiero, cita a Ernesto Piedras (The CIU) y Mony De Swaan (AMOMVAC), 13 may 2026. https://www.elfinanciero.com.mx/empresas/2026/05/13/registro-de-lineas-moviles-reporta-salto-en-menos-de-un-mes-crt-descarta-prorroga/

Business Cost and Market Structure

  1. Expansión, “Registro nacional… encarecerá los servicios de Telcel, AT&T y Bait”, 10 nov 2025. https://expansion.mx/tecnologia/2025/11/10/registro-nacional-lineas-moviles-encarecera-servicios-2026
  2. El Financiero, “Industria pide ‘tirarlo a la basura’”, 13 may 2026. https://www.elfinanciero.com.mx/empresas/2026/05/13/registro-obligatorio-de-lineas-moviles-industria-pide-tirarlo-a-la-basura-por-altos-costos-operativos/
  3. Diario Puntual, “Costará más de 4 mil millones de pesos a operadores”, 13 may 2026. https://www.diariopuntual.com/nacional/2026/05/13/4981/registro-obligatorio-de-lineas-moviles-costara-mas-de-4-mil-millones-de
  4. Expansión, dato de 3.45 pesos por intento en Altán Redes, 4 may 2026. https://expansion.mx/empresas/2026/05/04/operadores-moviles-pierden-usuarios-registro-telefonico
  5. El Financiero, cita el estudio de UBS Investment Bank, 1 oct 2025. https://www.elfinanciero.com.mx/empresas/2025/10/01/arranca-nuevo-padron-de-telefonia-movil-por-que-beneficia-a-telcel-y-complica-a-att-y-movistar/.
  6. El Financiero, “Slim parte con ventaja”, 3 oct 2025. https://www.elfinanciero.com.mx/empresas/2025/10/03/slim-parte-con-ventaja-por-que-el-nuevo-padron-de-telefonia-movil-beneficia-a-telcel/

The Security Incident on Telcel’s Portal

  1. Ignacio Gómez Villaseñor (@ivillasenor), tuit original con captura de DevTools, 10 de enero de 2026, 12:06 PM (1.5M vistas). https://x.com/ivillasenor/status/2010035485238763962.
  2. Ignacio Gómez Villaseñor (@ivillasenor), tuit sobre paquetes de suplantación con “prueba de vida” vendidos en foros de cibercrimen, 27 de abril de 2026, 10:51 AM (410.5K vistas). https://x.com/ivillasenor/status/2048822307066614007
  3. Quantum Secure Labs, “Vulnerabilidad en el registro de líneas móviles de Telcel provoca alarma”, 14 ene 2026. https://qsecure.es/vulnerabilidad-en-el-registro-de-lineas-moviles-de-telcel-provoca-alarma-tras-inicio-del-registro-obligatorio/
  4. OWASP Foundation, “API1:2023 Broken Object Level Authorization”, OWASP API Security Top 10 (2023). https://owasp.org/API-Security/editions/2023/en/0xa1-broken-object-level-authorization/.
  5. National Institute of Standards and Technology, “Secure Software Development Framework (SSDF) Version 1.1”, NIST SP 800-218. https://csrc.nist.gov/projects/ssdf.
  6. El Imparcial, “Telcel negó filtración de datos… aunque admitió una ‘vulnerabilidad técnica’”, 13 ene 2026. https://www.elimparcial.com/mexico/2026/01/13/telcel-nego-filtracion-de-datos-durante-registro-obligatorio-de-lineas-de-celular-con-curp-aunque-admitio-una-vulnerabilidad-tecnica/
  7. Expansión, cita a Víctor Ruiz (CEO de Silikn) y las 20 carpetas de investigación de la Secretaría Anticorrupción y Buen Gobierno, 12 ene 2026. https://expansion.mx/empresas/2026/01/12/telcel-niega-filtracion-masiva-de-datos
  8. Etcétera / Sisa Consultores, documenta que el endpoint comenzó a devolver valores null tras hacerse pública la falla, 11-13 ene 2026. https://etcetera.com.mx/opinion/exposicion-masiva-datos-celulares-falla-critica/
  9. Xataka México, sobre la posibilidad de automatizar consultas contra bases de números filtrados. https://mobiletime.la/noticias/13/01/2026/lineas-moviles-registro-mexico/

International Regulatory Precedents

  1. TeleSemana, “Casi mil días y un sinfín de multas para operadores peruanos”, 23 sep 2019. https://www.telesemana.com/blog/2019/09/23/el-sistema-biometrico-lleva-casi-mil-dias-y-un-sinfin-de-multas-para-operadores-peruanos/
  2. Revista Gan@Más, RENIEC y el fin del sistema biométrico actual en 2026. https://revistaganamas.com.pe/reniec-detecta-uso-irregular-de-consultas-biometricas-y-anuncia-el-fin-del-sistema-actual-en-2026/
  3. TrámitesPerú, verificado contra Resolución 00024-2026-CD/OSIPTEL y Decreto Legislativo 1738. https://tramitesperu.com/osiptel/checa-tus-lineas/
  4. ANATEL (Brasil), cronología del Cadastro Pré-Pago 2019-2021. https://www.diariogm.com.br/tecnologia/consulta-de-pre-pagos-por-cpf-esta-disponivel-para-as-regioes-centro-oeste-e-nordeste-a-partir-de-amanha-15-1
  5. Vivo (Brasil), referencia a Ley 10.703/2003 y Resolución 477/2007 de ANATEL. https://vivo.com.br/para-voce/comunicados/regulatorios/cadastramento-de-pre-pago/recadastro-de-pre-pago
  6. Diario de Cuyo, San Juan, Argentina, ENACOM, 11 oct 2018. https://diariodecuyo.com.ar/sanjuan/En-San-Juan-hay-plazo-hasta-el-proximo-jueves-para-registrar-una-linea-prepaga-20181011-0038.html
  7. Notebookcheck, Alemania, artículo 111 de la Telekommunikationsgesetz, 1 jun 2016. https://www.notebookcheck.com/Deutschland-Ausweispflicht-beim-Kauf-von-Prepaid-Karten.167226.0.html

Black Market of Pre-Registered SIM Cards

  1. Expansión, “Huachicoleo de chips ya registrados”, 20 ene 2026. https://expansion.mx/empresas/2026/01/20/huachicoleo-de-chips-ya-registrados-55-pesos-facebook
  2. Diario de Yucatán, 20 ene 2026. https://www.yucatan.com.mx/mexico/2026/01/20/alertan-por-venta-de-chips-ya-registrados-tras-obligacion-de-registro-celular.html
  3. El Imparcial, precios de 27 a 1,000 pesos, credenciales del INE falsas, 20 ene 2026. https://www.elimparcial.com/mexico/2026/01/20/no-quieres-perder-tu-linea-telefonica-pero-tampoco-quieres-darle-tus-datos-al-gobierno-comerciantes-venden-chips-ya-registrados-curp-generadas-y-credenciales-del-ine-falsas-tras-nueva-norma-federal-los-precios-van-desde-27-pesos-hasta-mil-pesos/
  4. Tribuna Económica, 23 ene 2026. https://tribunaeconomica.com.mx/publicaciones/seccion/nacional/registro-celular-venden-chips-presuntamente-vinculados-a-curp-listos-para-usar/
  5. Xataka México, compra propia de chip de Movistar por 200 pesos, 29 may 2026. https://www.xataka.com.mx/telecomunicaciones/mexico-queria-eliminar-anonimato-telefonico-registro-lineas-venden-chips-registrados-200-pesos
  6. El Mañana de Nuevo Laredo, mercado en comercio físico de Guadalajara, 17 jun 2026. https://www.elmanana.com.mx/nacional/2026/6/17/registro-telefonico-en-mexico-2026-dias-de-la-fecha-limite-crece-la-venta-de-chips-anonimos-178539.html

Biometric Data in Carriers’ Practice

  1. Grupo Milenio, registro Bait. https://www.milenio.com/comunidad/registro-de-celular-bait-link-para-vincular-tu-numero-guia
  2. Grupo Milenio, “¿Piden datos biométricos? Esto dice la CRT”. https://www.milenio.com/comunidad/debes-registrar-datos-biometricos-linea-telefonica-curp-crt
  3. Xataka México, criterio de un tribunal federal sobre eliminación de biométricos. https://www.xataka.com.mx/telecomunicaciones/expertos-lanzan-alerta-telcel-at-t-movistar-bait-usaron-tus-datos-biometricos-para-validar-tu-identidad-deben-eliminarlos
  4. Grupo Animal / El Sabueso, cómo evitar biométricos acudiendo presencialmente. https://grupoanimal.mx/explicaciones/registro-linea-telefonica-datos-biometricos
  5. El Informador, qué es la Prueba de Vida y por qué genera controversia, 22 jun 2026. https://www.informador.mx/mexico/registro-de-celulares-con-la-curp-que-es-la-prueba-de-vida-y-por-que-hay-controversia-con-este-requisito-para-la-vinculacion-en-linea-20260622-0145.html

Fact-Checking the PANAUT / Current Registry Confusion

  1. El Heraldo de México, fact-check, 28 ene 2026. https://heraldodemexico.com.mx/nacional/2026/1/28/falso-que-el-registro-obligatorio-de-lineas-celulares-sea-inconstitucional-por-la-scjn-763799.html
  2. Yahoo Noticias, fact-check, 22 ene 2026. https://es-us.noticias.yahoo.com/falso-panaut-registro-obligatorio-l%C3%ADneas-082402782.html