China's Big Three Carriers Shut Third-Party Websites Out of SIM Card Sales
- Ethan Carter

- 3 hours ago
- 12 min read
China Telecom, China Mobile, and China Unicom closed third-party online SIM card ordering on August 1, creating an immediate break with a familiar sales model.
The three carriers announced the change on July 31, according to a newsflash report citing China Media Group. Customers ordering mobile numbers online must now use a carrier's official app, website, or another authorized first-party channel.
The decision is more than a routine channel adjustment. It moves identity documents, facial verification, order records, and activation data away from outside storefronts. That shift gives carriers direct control over the riskiest parts of customer acquisition.
Third-party platforms and independent online dealers face the most immediate pressure. They previously helped carriers reach price-sensitive customers, compare plans, and distribute cards beyond physical stores. Now the same distance that made those channels useful has become a compliance liability.
What Changed on August 1
China's three national carriers have replaced distributed online SIM sales with a first-party ordering model.
The notices reportedly took effect one day after publication. From August 1, customers seeking a new mobile number through the internet must begin the transaction through an official carrier channel.
The policy concerns online ordering and activation of telecommunications number cards, commonly called SIM cards. It does not mean every physical dealer has closed, nor does it end online service. The defining change is who controls the digital transaction.
Customers can still order through official apps and carrier websites. The carriers can also identify other first-party portals as authorized channels. Third-party marketplaces, promotional pages, and independent traffic brokers can no longer complete the same card-ordering process.
This distinction matters because a SIM order includes more than a product shipment. It creates a regulated telecommunications account linked to a verified identity. The operator must know who applied, which credentials were checked, where the card went, and how activation occurred.
A marketplace can display a handset without becoming part of the mobile network's identity system. A SIM card is different because it becomes an authentication tool for calls, payments, social accounts, and online services.
The carrier notices frame the restriction around user rights, data protection, and consistent management. That language points to a control problem rather than a lack of demand for online sales.
Under the previous model, a customer might discover an offer on a marketplace, submit personal information through an outside storefront, receive a card by courier, and activate it remotely. Several companies and software systems could touch the transaction.
The new model reduces those handoffs. Discovery can still happen elsewhere, but the regulated order should move onto infrastructure controlled by the carrier.
That produces a clear boundary. Third parties can advertise, compare, or refer customers where permitted, but they cannot act as the online counter that completes the subscription.
The reported notices do not provide detailed implementation rules for every affiliate, embedded page, or referral arrangement. Customers should therefore judge a channel by where the application is processed, not merely by where a promotion appears.
An official logo is not enough. The order page, privacy notice, identity check, payment recipient, and customer support path should all identify the carrier or its clearly authorized service.
The change also does not automatically invalidate existing cards purchased through outside channels. The announcement concerns new online ordering from the effective date. Existing customers remain subject to their service agreements and normal identity requirements.
For buyers, the practical instruction is simple. Start in an official carrier app or type the carrier's verified web address directly. Avoid sending identity documents to a seller through chat, email, or an unfamiliar form.
That narrower path creates some inconvenience, but it also makes accountability easier to trace. When the carrier owns the complete order, it becomes harder to blame an invisible subcontractor after data leaks or fraudulent activation.
Why Carriers Want Identity Checks Under One Roof
The strongest reason for centralization is that SIM distribution sits at the intersection of personal data, regulated identity, and fraud prevention.
China has required real-name registration for phone users for more than a decade. The Ministry of Industry and Information Technology's registration rules took effect in September 2013.
Those rules require telecommunications operators to inspect valid identification and record the subscriber's real information. An operator cannot complete registration when a customer refuses identification or presents false credentials.
Internet sales made that duty harder to supervise. A physical employee can inspect a document and compare it with the person standing at a service desk. A remote transaction needs technical substitutes for that encounter.
In 2016, regulators specifically identified weak registration practices in online marketing channels. They required online sellers to verify identity information before delivery and confirm the recipient during handoff.
The same 2016 guidance called for network checks of identification data. It also required consistency among the buyer, submitted credentials, and final recipient.
Those controls can work across an agent network, but every additional participant creates another place where implementation can drift. A dealer can use an outdated interface, retain documents unnecessarily, or prioritize completed sales over rejected applications.
Centralization gives carriers a common workflow. They can apply the same document checks, risk signals, consent language, retention rules, and activation conditions to orders across provinces.
It also improves auditability. A carrier can examine one transaction log to determine when an application began, which verification completed, what device submitted it, and where the card was delivered.
That does not guarantee perfect security. Central systems can still be attacked, misconfigured, or used improperly. However, direct control removes uncertainty about which outside seller collected a document or stored a copy.
SIM registration involves particularly sensitive information. An applicant may provide an identification number, name, address, portrait, delivery location, and live facial image. Together, those fields can expose far more than a shopping preference.
The danger is not limited to a conventional data breach. Identity material collected during a legitimate-looking application can support impersonation, account creation, or social engineering elsewhere.
A carrier also needs to understand whether the person ordering a card intends to use it. Fraud networks often rely on cards registered under another person's identity, obtained through deception, or transferred after activation.
China's Anti-Telecom and Online Fraud Law made operator responsibility explicit. Article 9 requires carriers and mobile resellers to enforce real-name registration, including oversight of agents.
The anti-fraud law also lets operators strengthen checks or reject suspicious applications. It requires renewed verification when a card displays fraud-related risk.
That framework changes the economics of distribution. A carrier gains revenue when a dealer adds a legitimate subscriber, but it retains regulatory exposure when the same dealer admits a fraudulent one.
The outside seller receives the benefit of conversion. The carrier inherits the long-term cost of monitoring, complaints, investigation, and possible enforcement. Direct ordering brings the sales decision closer to the party carrying that risk.
Centralization can also improve data minimization, which means collecting only information needed for a defined purpose. A carrier can prevent storefronts from adding unnecessary marketing fields to a regulated identity process.
The key test will be implementation. A first-party page should clearly explain what data it collects, why it needs each item, how long records remain, and how customers can correct errors.
Without those details, moving data to official channels changes custody but does not resolve every privacy concern. The new boundary is a starting point for better governance, not proof that every transaction is safe.
The Real Contest Is Distribution Versus Accountability
The policy chooses direct accountability over the reach and flexibility of third-party distribution.
Outside channels solved a genuine business problem. Major marketplaces already had customer traffic, search tools, payment systems, promotion engines, and nationwide delivery relationships.
Independent dealers could package plans for narrow audiences. They could explain regional offers, advertise large data allowances, and reach people who rarely opened a carrier's app.
That model lowered the cost of finding a customer. It also made carrier plans easier to compare beside unrelated products and rival offers.
Yet the same structure fragmented responsibility. A customer could see one company in an advertisement, another on the checkout page, and a third on a courier message. The carrier's name might appear only during activation.
When something went wrong, the customer had to determine whether the seller, marketplace, logistics provider, or carrier controlled the disputed step.
The July 31 notices reverse that arrangement for online card processing. Carriers are accepting more responsibility for digital acquisition while giving up some outsourced reach.
Third-party sellers lose more than a product listing. SIM offers often served as a traffic and commission business built around targeted advertisements, affiliate links, and limited promotional packages.
Some merchants can shift toward referral marketing. They may explain an offer and send the customer to an official application page. However, the carrier can now observe the conversion directly and impose tighter rules on attribution.
Other sellers have less room to adapt. A business whose main value came from collecting applications or navigating carrier systems on a customer's behalf no longer fits the stated model.
Marketplaces also lose a useful category for customer engagement. Mobile plans encourage comparisons and recurring interest, especially when promotions combine data allowances with other benefits.
Carriers gain a cleaner customer relationship. They can present official terms, capture consent, handle verification, and provide support without reconstructing what an outside seller promised.
That control can reduce misleading promotions. Third-party advertisements sometimes emphasize an attractive allowance while placing eligibility, geographic restrictions, or renewal conditions in less prominent text.
An official channel is not immune to confusing marketing. It is simply easier to identify the responsible company and preserve the exact terms shown during checkout.
There is also a competitive tradeoff among the carriers themselves. Large operators already own widely used apps, websites, stores, and customer-service systems. Smaller regional sellers depended more heavily on borrowed traffic.
China Mobile, China Telecom, and China Unicom can absorb traffic into their existing properties. However, each must now make those properties effective enough to replace the convenience that outside sellers provided.
A customer who cannot find a plan, finish identity verification, or obtain help may abandon the transaction. Centralization turns that lost sale into the carrier's direct problem.
This is why the move should not be read as a retreat from online distribution. It is an attempt to rebuild online distribution around controlled identity infrastructure.
The carrier remains free to advertise broadly. It can work with media companies, comparison services, or affiliates for customer discovery. The critical line appears at the point where browsing becomes a regulated application.
That division resembles other internet markets where platforms can generate leads but licensed providers must complete sensitive transactions. The promotional layer stays open while the identity and contract layer narrows.
The balance will depend on enforcement. If unofficial sellers continue processing applications through disguised forms, compliant dealers will lose business without producing the promised security improvement.
Carriers must therefore monitor more than storefront names. They need to detect reused application interfaces, shared credentials, unauthorized data collection, and promotions that misrepresent official status.
Marketplaces have a role as well. They can remove listings that offer unauthorized activation, preserve evidence for disputes, and prevent merchants from returning under slightly different descriptions.
For customers, accountability becomes the central benefit. A buyer should no longer need to guess which company handled a face scan or whether a dealer retained an identification image.
For the distribution industry, accountability becomes the central cost. Businesses that once participated deep inside the order flow must either move outward into advertising or exit the category.
Official Channels Reduce Risk, but They Also Create New Pressure
Closing outside ordering channels reduces one class of exposure while concentrating service, accessibility, and security risks inside three carrier systems.
The first uncertainty is customer experience. Official apps can be large, crowded, or designed mainly for existing subscribers. A new customer may struggle to register before having a carrier number.
Websites can present a different problem. Regional plan availability and identity requirements may vary, while national landing pages do not always explain those differences clearly.
Third-party merchants sometimes filled that gap through human assistance. They answered questions in familiar marketplace chats and helped customers compare complicated conditions.
Removing transaction authority does not remove the need for guidance. Carriers must offer responsive support without asking an unverified intermediary to handle personal documents.
Accessibility deserves special attention. Older customers, people with disabilities, and users with older devices can face barriers during facial verification or app-based ordering.
A safe first-party process needs alternatives. These might include an official web flow, accessible customer service, or a physical service location when remote verification fails.
Geography also matters. Customers in rural areas may rely more heavily on delivery because a carrier store is distant. A stricter online model should not quietly become a requirement to travel.
The second uncertainty is whether centralization improves privacy in practice. Concentrating applications in one system reduces third-party exposure, but it also creates a valuable target containing many identity records.
Carriers need strict access controls, encryption, short retention periods where permitted, and monitoring for employee misuse. A recognizable domain cannot substitute for those protections.
Phishing will also adapt. Criminals can copy an official app's design, buy similar domain names, or send messages claiming that a customer must repeat identity verification.
The new policy may even give such messages a convincing story. A fraudulent page can claim that third-party orders must be migrated into an official system.
Customers should navigate independently to a known app or verified website. They should not trust an identity-check link merely because it mentions the August policy.
The third uncertainty involves the boundary around authorized promotion. The announcement says third-party internet channels will no longer provide card-processing services, but public summaries do not define every permitted marketing relationship.
Can a comparison page show current plans? Can an affiliate prefill a non-sensitive referral code? Can a marketplace host an official carrier-operated storefront whose application runs entirely on carrier infrastructure?
The answers will shape the commercial impact. A strict ban on all third-party discovery would be much broader than a ban on third-party processing.
The reported language supports the narrower interpretation. It directs customers to official ordering channels and removes outside providers from card handling. It does not establish that carriers must stop advertising elsewhere.
Clear carrier guidance would help legitimate partners avoid accidental violations. It would also help platforms distinguish a prohibited merchant from an official carrier presence.
The fourth uncertainty is enforcement against existing gray-market offers. Removing compliant listings is easy. Finding sellers who move into private chats, short-video promotions, or changing web domains is harder.
China has already built tools for monitoring risky cards and accounts. In 2023, the Ministry of Industry and Information Technology said industry systems had blocked more than 4.5 billion fraud-related calls and messages.
The same enforcement update reported checks or action involving nearly 200 million high-risk internet accounts. Those figures show the scale of the broader enforcement system.
They do not prove that third-party SIM sales caused those incidents. The carrier notices should not be used to label every independent dealer as fraudulent.
Many outside sellers likely followed carrier procedures and served legitimate customers. The policy reflects the difficulty of governing a large, uneven network, not a finding that every participant misused data.
That distinction matters for fair analysis. Central control can reduce variation, but regulators and carriers should still explain how lawful partners can transition.
Consumers also need workable remedies when an official system rejects them. Automated risk controls can produce false positives, especially for people with unusual travel patterns, repeated delivery failures, or past number disputes.
The anti-fraud law recognizes the need for differentiated measures and appeal paths. A centralized order model should make those paths visible at the moment of rejection.
Otherwise, a security control can become an unexplained denial of a basic communications service. The strongest system is not the one that rejects the most applications. It is the one that distinguishes legitimate customers accurately.
Three Signals Will Show Whether the Policy Works
The next three months should reveal whether this is a durable security reform or mainly a rapid channel shutdown.
The first signal is the disappearance of functional third-party order forms. Search results and marketplace listings will show whether merchants have stopped collecting identity details and arranging activations.
A real transition should move the regulated application onto a carrier-controlled domain or app. Promotions that still request identification images, facial scans, or activation videos would weaken the policy's central claim.
Enforcement should also distinguish between advertising and processing. Referral links can remain useful when they lead clearly to official infrastructure. Disguised order forms should not.
The second signal is customer friction inside official channels. Watch for complaints about failed verification, unavailable plans, delivery restrictions, inaccessible apps, and unclear rejection notices.
A short adjustment period is expected after a sudden migration. Persistent problems would show that carriers removed distribution capacity faster than they replaced it.
Carriers should publish practical instructions covering valid channels, delivery, activation, accessibility, support, refunds, and appeals. They should also provide a direct way to report impersonating websites.
The third signal is whether identity and fraud outcomes improve. The most meaningful evidence would include fewer unauthorized card registrations, fewer complaints about document misuse, and fewer fraud-linked cards originating from online applications.
Users can already check how many mobile cards are registered under their identity through the national card-checking service. Increased use could help expose registrations that customers did not authorize.
No single number will settle the question. Fraud trends reflect enforcement, criminal adaptation, economic conditions, and activity across many communications services.
Still, the policy creates a testable proposition. If direct ordering improves traceability, carriers should be able to identify suspicious applications earlier and resolve customer disputes with better records.
The wider lesson reaches beyond China's telecommunications market. Digital distribution works well when a product carries limited identity risk. It becomes harder when a transaction creates access to communications, finance, or government services.
Third-party channels maximize reach by dividing the customer journey among specialists. Regulated identity systems work best when responsibility remains visible from application through activation.
China's carriers have now chosen the second priority for online SIM orders. The decision narrows consumer choice at checkout, but it also establishes a clearer answer when someone asks who handled their identity.
Customers ordering a new number should begin with a verified carrier app or website, inspect the privacy notice, and preserve the displayed plan terms. They should leave any page that requests documents through private messages or redirects them between unexplained domains.
The decisive question is no longer whether official channels can accept orders. It is whether they can match outside sellers' convenience while producing fewer fraudulent registrations, fewer data disputes, and clearer remedies for legitimate users.


