Iraq regulator urges Korek users to switch authentication numbers amid service uncertainty

Iraq’s Communications and Media Commission has advised Korek Telecom users in the Kurdistan Region to add an alternative mobile number from another licensed operator to their digital accounts, warning that users could lose access to services if verification and authentication messages stop arriving on Korek numbers.

The regulator said Korek customers who rely on their mobile numbers for social media logins, account recovery and other digital authentication processes should take precautionary steps now rather than wait for messaging disruptions to occur.

The guidance follows the CMC’s June decision to cancel its contract with Korek Telecom and suspend the operator’s activities over alleged breaches of contractual obligations.

Users advised to add a second number where possible

For platforms that allow more than one mobile number to be registered, the CMC recommended that Korek users add a number from another licensed operator and use that alternative for verification codes, authentication messages and account recovery.

Where a platform permits only one phone number, the regulator advised users to replace their Korek number with one from Asiacell or Zain Iraq.

The CMC also encouraged customers to adopt alternative authentication methods, including email and authenticator applications.

The regulator stressed that users should complete these changes before they stop receiving verification messages.

CMC says guidance is precautionary, not a call to abandon Korek

The commission said the measures are intended to protect users’ data and access rights rather than encourage them to cancel or abandon their existing Korek numbers.

The guidance is specifically focused on maintaining access to digital accounts that depend on SMS-based verification.

That distinction is important because users may continue to retain their Korek numbers even while adding more resilient authentication options elsewhere.

Korek dispute has already disrupted services

The advisory comes after a prolonged dispute between Korek Telecom and Iraqi authorities.

In June, the CMC cancelled its contract with Korek and suspended operations, citing alleged contractual breaches and non-compliance with agreement requirements.

Korek CEO Sirwan Barzani rejected the move as unlawful and said legal action would be pursued.

The operator had already faced service disruption before that decision.

In November 2023, the CMC blocked incoming and outgoing communications between Korek and other carriers over unpaid financial obligations, according to the source.

Mobile numbers have become critical digital identity tools

The CMC’s warning highlights how deeply mobile numbers are now embedded in digital identity and account security.

Many users rely on SMS codes for two-factor authentication, password resets and account recovery across banking, social media, messaging and government services.

If a mobile number becomes unreliable or stops receiving verification messages, users can be locked out even if the underlying account remains active.

That makes telecom service continuity increasingly relevant to cybersecurity and digital identity, not just voice and data access.

Why this matters

The CMC’s guidance reflects a practical digital security risk created by telecom service uncertainty.

For Korek users, the immediate concern is not simply degraded mobile service, but the possibility of losing access to online accounts that depend on their phone number.

The regulator’s recommendation to add alternative numbers and non-SMS authentication methods is therefore a continuity measure aimed at reducing dependence on a single telecom identity channel.

Editor’s note

The most significant part of this development is the intersection between telecom regulation and digital identity.

A mobile number is no longer just a communications endpoint. For many users, it is also an authentication credential tied to financial, social and personal accounts.

The Korek situation shows how regulatory or commercial disruption at a telecom operator can spill directly into account security. It also reinforces the case for users and platforms to rely less heavily on SMS as the sole recovery and verification mechanism.