The Public Authority for Civil Information notified citizens and residents using the Hawiti application not to approve authentication requests unless those requests follow an action the user initiated. PACI posted the advisory on its official X account at @pacikwt and called for verification of the service provider’s details together with the exact purpose of any authentication before acceptance. The authority framed the measure as essential to preserving information security and ensuring safe application usage across digital platforms. This guidance builds on the system’s role in daily transactions for both government services and private sector interactions.
PACI stated in the December 11, 2025, post that users must treat every prompt with caution even when it appears to originate from a trusted bank or ministry. The authority added that unsolicited requests could expose personal data or facilitate unauthorised transactions if approved without scrutiny. Officials directed recipients to reject any uninitiated prompt and to contact the claimed provider only through established official channels listed on the PACI website. Such practices align with repeated public education campaigns the authority has conducted since the application’s wider rollout.
Google Play figures show the Kuwait Mobile ID application has exceeded 5 million downloads since its launch with an average rating near 3.9 stars from more than 50,000 user reviews. The platform functions as a portable digital civil ID that supports identity verification, access to e-services and the application of trusted electronic signatures on documents. PACI developed the tool to include a credential wallet for items such as driving licences that users can present through QR codes at checkpoints or service counters.
A Kuwait News Agency dispatch in August 2025 carried a parallel PACI message that similarly restricted approvals to self-initiated transactions only. Gulf Bank participated in the Central Bank of Kuwait’s Diraya awareness campaign in January 2025 by highlighting cases in which customers had approved Mobile ID prompts without confirming their origin. These joint efforts responded to patterns of social engineering that exploit the cross-device authentication flow the application employs.
PACI previously denied social media rumours of a cyberattack on the Mobile ID system in a March 2026 statement that confirmed all backend operations remained secure and uninterrupted. The authority has since introduced updates that allow activation of digital signatures without visits to self-service kiosks while maintaining strict backend protections. Support for users is available through the dedicated [email protected] address or the in-app chatbot hosted on the official Hawiti portal.
The advisory forms part of PACI’s continuing modernisation of civil information services that now handle a rising volume of electronic identity checks each month. Public Authority for Civil Information data indicate the application has reduced physical counter traffic at residency and civil registry offices by enabling remote verification for permit renewals and record updates. Users who encounter repeated suspicious prompts can reinstall the application and re-register their civil ID to restore full functionality under the authority’s recovery protocols.