Author: Vijay Amirthraj

  • Qué tan grande es el impacto del fraude de la IRSF y 5 estrategias simples para controlar la IRSF

    Qué tan grande es el impacto del fraude de la IRSF y 5 estrategias simples para controlar la IRSF

    El fraude internacional de participación en los ingresos (IRSF) es uno de esos tipos de fraude que ha estado vivo durante dos décadas, todo debido a que el fraude es intrincado en su patrón, mientras que el enfoque sigue siendo muy reactivo. Aquí, el motivo del defraudador es recibir la participación en los ingresos del cargo en los números premium internacionales. Los estafadores abusan de la infraestructura del operador de telecomunicaciones para inflar artificialmente el tráfico en destinos internacionales de alto riesgo con la intención de impago. Este fraude es común en todas las geografías y tiene una pérdida por fraude estimada de USD 5.04 mil millones (el mayor contribuyente a la pérdida por fraude) según la Encuesta global de pérdida por fraude de la Communications Fraud Control Association (CFCA), 2019.

    La falta de medidas adecuadas tomadas para proteger la red ha provocado que este fraude crezca a pasos agigantados. En este fraude, el atacante generalmente intenta explotar las vulnerabilidades de los activos y ataques del proveedor de servicios de telecomunicaciones llamando a rangos de números no asignados o llamadas terrestres a servicios internacionales con calificación premium o enrutando ilegítimamente las llamadas a teléfonos móviles detenidos en corto tiempo. El fraude de suscripción, piratería de PBX, margen de arbitraje, clonación de SIM, robo de dispositivos y abuso de servicios promocionales son a menudo los métodos comúnmente utilizados para ejecutar las prácticas fraudulentas. El fraude también es bastante común con muchos proveedores de línea fija.

    En mi experiencia de trabajo con múltiples operadores, a nivel mundial, siento que el desafío más común que enfrentan los operadores es comprender el patrón de fraude y el método utilizado por el atacante. El impacto sobre el operador se vuelve brutal cuando los estafadores utilizan patrones de ejecución desconocidos y técnicas sofisticadas para atacar la red. Los ataques de IRSF desde la red de roaming, conferencias telefónicas, desvío de llamadas, tarjetas telefónicas, abuso de margen negativo para productos y servicios se encuentran entre los métodos más populares para un estafador al lanzar ataques.

    Además, la falta de precedencia regulatoria en la regulación de la forma de hacer negocios con los transportistas internacionales no es lo suficientemente estricta, lo que establece el caldo de cultivo perfecto para que prosperen los estafadores.

    ¿Por qué este fraude ha crecido a pasos agigantados y se puede garantizar la proactividad del control?

    Los mecanismos tradicionales y reactivos de lucha contra el fraude a la fecha no tienen una solución completa y una de las principales razones es que no existen suficientes estrategias, mecanismos y sistemas de control del fraude. La IRSF, a diferencia de otros tipos de fraude, requiere una medida de control continua y proactiva. Más que solo las técnicas de detección “comunes y corrientes”, el tipo de fraude requiere un control bien planificado y una estrategia de dirección de mitigación y aquí hay seis estrategias simples, para empezar:

    • Las prácticas fraudulentas se han vuelto más inteligentes con el tiempo.

    Si nos jactamos del hecho de que las tecnologías de detección de fraude se han vuelto bastante sofisticadas con el tiempo, no debemos olvidar que las prácticas de fraude también han ganado la misma cantidad de inteligencia. Los estafadores en estos días se dan cuenta rápidamente de las lagunas tecnológicas y las fallas del sistema. Hoy en día, los estafadores no necesitan mucho para detectar los patrones de detección de fraudes y la lógica de control de los CSP e identificar la laguna en el sistema. Para contrarrestar el intento de IRSF del estafador, el estudio del método y el patrón se convierte en un proceso crítico. Además, el uso de la técnica de monitoreo SIP para identificar dispositivos / herramientas como SIP vicious puede ayudar a las empresas de telecomunicaciones a prevenir IRSF. Se puede utilizar una combinación de técnicas y modelos de IA/ ML para detectar nuevos patrones de fraude de IRSF con automatización y crear inteligencia de IRSF, por ejemplo: tendencias en patrones de llamadas.

    • Desmoralice a su atacante de la IRSF

    ¿Dejar que tu atacante te ataque para cavar su propia tumba suena como un oxímoron? ¡En realidad no! De hecho, es posible tener un sistema de honey-trap (trampa) en el lugar donde atraes al atacante para que lance los ataques sin un resultado fructífero. Cuanto más fallan los intentos del atacante, menos esperanzadores se esfuerzan más. Además, la recopilación de inteligencia de proveedores confiables que pueden proporcionar información sobre grupos de fraude destacados y respaldar el bloqueo quirúrgico de rangos de números internacionales ha demostrado ser una estrategia exitosa a nivel mundial para contrarrestar la IRSF.

    • Piense en el cliente y proteja sus intereses

    El IRSF no solo agota los recursos de ingresos, sino que también puede causar insatisfacción en el cliente, lo que eventualmente hará que abandonen la red. El IRSF no solo apunta a las cuentas minoristas, sino que los clientes empresariales son un grupo de riesgo clave que le cuesta millones de dólares al operador de telecomunicaciones. Por lo tanto, es fundamental que no ignoremos cuando un cliente se queja de frecuentes conexiones cruzadas o desvíos de llamadas para llamadas internacionales.

    • Tenga una estrategia de vigilancia “en cualquier momento y en cualquier lugar” con la automatización a su favor

    Los procesos de detección de IRSF pueden ser complicados y a veces requieren muchos recursos. Sin embargo, tener las estrategias correctas, los procesos correctos con la cantidad adecuada de automatización aplicada puede ayudar a la empresa de manera significativa. Personalmente recomiendo que se implemente una estrategia de detección

    24 x 7 para contrarrestar los ataques de la IRSF. De los casos que he tratado, mi observación es que, aunque los ataques IFRS ocurren las 24 horas del día, sin embargo, las primeras horas de la mañana o fuera del horario comercial son un objetivo crítico. Tener una estrategia de mano de obra rotatoria realmente puede hacer maravillas a veces. Sin embargo, también podría haber casos en los que no sea posible tener un enfoque 24 x 7 debido a la falta de capital o al alto costo de los recursos humanos. En tales casos, será valiosa una combinación de la automatización de los procesos de detección y las operaciones intensivas en humanos durante horas cruciales.

    • Nunca ignore los márgenes negativos

    Los márgenes negativos pueden ocurrir en cualquier nivel. Podría surgir en la planificación de las estrategias de precios de los productos, servicios, uso de tarjetas telefónicas en destinos internacionales o acuerdos de interconexión. Los márgenes débiles de las ganancias a menudo pueden abrir una caja de Pandora para los estafadores. Solo el conocimiento básico sobre los márgenes negativos es suficiente para que los estafadores rompan el caos. Los informes de tendencias sobre patrones de tráfico con prioridades asignadas a asociaciones con márgenes frugal pueden salvar el día.

    • Buscar asociaciones estratégicas de conocimiento para establecer información sobre los estafadores.

    Compartir conocimientos y tener un ecosistema de apoyo para la interacción con los proveedores de servicios y proveedores en la cadena de valor puede ser un paso práctico más cercano a la proactividad. Además, los memorandos de entendimiento establecidos con foros de la industria y CoE como GSMA, CFCA, RAG Blockchain para Wangiri y otros pueden ayudar a los CSP a obtener información como números de prueba y servicios PRS, números de rango de alto riesgo, series de números no asignados que pueden usarse como fuentes vitales de referencias para contrarrestar este fraude. Los operadores de telecomunicaciones también pueden fortalecer la defensa interna mediante el establecimiento de controles de servicio, por ejemplo,  restricciones sobre el uso de capacidades internacionales y de roaming para ciertos clientes. Y restrinja el desvío de llamadas internacionales, llamadas multipartitas, etc.

    Cuando digo un enfoque reactivo para la detección de fraudes IRSF basada en AI / ML, me refiero a que gran parte del esfuerzo y los sistemas construidos para contrarrestar el fraude están en silos y también lo son los esfuerzos humanos que se realizan. Por un sistema proactivo, me refiero a un sistema que está bastante unificado en su enfoque y puede realizar operaciones de extremo a extremo asociadas con el tipo de fraude. Un sistema de gestión de fraude proactivo marcará la primera llamada en roaming, rastreará desviaciones significativas en el comportamiento de uso, altos volúmenes de tráfico internacional a destinos de alto riesgo, marcación secuencial, etc. y lo combinará con el uso de bases de datos de conocimiento como la inteligencia de datos de Subex IRSF, que incluye rangos de números no asignados, rangos de alto riesgo, números fraudulentos conocidos para respaldar el bloqueo basado en la red y / o la integración para la identificación temprana de comportamientos de alto riesgo y bloqueo automatizado, cuando sea necesario.

    Una de las muchas formas de construir un sistema más proactivo y unificado es seguir el camino de la IA (Inteligencia Artificial). Una estrategia de tecnología de IA bien pensada realmente puede ayudar a detectar el fraude en una etapa muy temprana y ayudarlo a elegir los controles adecuados para problemas específicos en cuestión. Su objetivo es reducir el tiempo que toman los laboriosos esfuerzos humanos que entran en la etapa de detección mientras ayuda a los analistas e investigadores a concentrarse en la necesidad del momento. Por mucho que diga el famoso refrán inglés “Toda nube tiene un lado positivo”, el impacto de la IRSF se puede reducir considerablemente simplemente ampliando las perspectivas organizacionales hacia el fraude.

    Subex se ha asociado recientemente con Biaas para la inteligencia de datos de IRSF, para saber cómo puede beneficiarse de esta asociación

    Descarga el folleto

  • ¿Cómo luchan los gestores de fraude en la industria de las telecomunicaciones a los estafadores?

    ¿Cómo luchan los gestores de fraude en la industria de las telecomunicaciones a los estafadores?

    Actualmente enfrentamos un brote global de COVID-19 con el consiguiente bloqueo, pánico y miedo en todo el mundo. Hemos seguido con atención los medios de comunicación para mantenernos actualizados sobre la situación. Si bien, de manera muy alentadora, más del 95% de la fuerza laboral ha comenzado a trabajar desde casa con una posible conectividad segura, los estafadores también han estado igualmente activos, buscando oportunidades para atacar a los suscriptores en todo el mundo. En el último mes, ha habido un fuerte aumento en la incidencia de IRSF, llamadas automáticas, estafas por SMS, fraude de ingeniería social, DDoS y ataques cibernéticos.

    Los operadores y los clientes han estado enormemente tensos durante las últimas semanas. Necesitamos estar a la altura de las circunstancias para proteger sus intereses. Según lo vemos desde Subex, se pueden seguir los siguientes pasos para enfrentar los desafíos relacionados con el fraude de las telecomunicaciones:

    • Conciencia del suscriptor: se debe lanzar un programa de concientización del suscriptor de inmediato para que los consumidores desconfíen de los diversos esquemas fraudulentos que surgen durante el período de pánico y miedo. Un caso puntual según lo informado por uno de los operadores asiáticos es que la semana pasada muchos suscriptores que habían instalado las aplicaciones de actualización en vivo COVID-19 en sus teléfonos recaudaron la friolera de $ 0.16 Mn porque no sabían que las aplicaciones también tomarían el estado del teléfono, incluida la función de lectura y escritura de SMS.
    • Priorizar el monitoreo de alertas de fraude: el trabajo remoto tendría sus desafíos. Los equipos de gestión de fraudes deben priorizar las alertas, especialmente las que tendrían un mayor impacto en los suscriptores y actuar en consecuencia y fijarlas en prioridad.
    • Acciones correctivas de causa raíz: la solución ideada para eliminar las causas de la actividad fraudulenta reducirá las probabilidades de su recurrencia. Por ejemplo, en la red, el rango de los números de destino de alto riesgo puede bloquearse por un corto período si se detecta un ataque de fraude IRSF.
    • Comunicación y colaboración: debemos estar conectados digitalmente a todas las partes interesadas para que actúen con dureza en actividades fraudulentas en la red. El SLA con las partes interesadas puede ser refinado y ajustado adecuadamente para una acción más rápida. Este es uno de los elementos clave cuando todo el equipo trabaja de forma remota para respaldar las operaciones diarias.
    • Actualizaciones periódicas sobre los patrones de fraude emergentes / recientes: visite con frecuencia los foros de fraude para estar al tanto de los patrones de fraude emergentes / recientes elaborados por los estafadores. Los delincuentes siempre están atentos a arruinar los procesos y sistemas para fines nefastos. Muchos operadores han informado un aumento en las llamadas automáticas, estafas por SMS y ciberataques durante este período.
    • Realización de la gestión del fraude como parte del Plan de continuidad del negocio (BCP): es muy importante incorporar la gestión del fraude como parte del BCP de manera importante y garantizar que tengamos la máxima cobertura durante este período.

    Según nuestros cálculos, los equipos de gestión de fraudes deberían estar más atentos y ágiles que nunca para enfrentar los nuevos desafíos del fraude de telecomunicaciones que se generalizaron durante este brote global de COVID-19. Los administradores de fraudes son superhéroes cuando se trata de generar confianza con los clientes.

    ¡Manténgase seguro y saludable!

    Para comprender cómo puede detectar y prevenir estafas y llamadas no deseadas utilizando modelos avanzados de aprendizaje automático

    Descargue el Estudio de Caso

  • Telecom fraud managers fight against fraudsters during COVID-19 crisis

    Telecom fraud managers fight against fraudsters during COVID-19 crisis

    There is now a global outbreak of COVID-19 with the resultant lock-down, panic, and fear across the globe. We have been keenly following the media to keep ourselves updated about the situation. While, very reassuringly, more than 95% of the workforces have started working from home with possible secure connectivity, fraudsters have also been equally active, looking for opportunities to attack the subscribers all over the world. In the past month, there has been a sharp increase in the incidence of IRSF, Robocalls, SMS Scams, Social Engineering fraud, DDoS and cyber-attacks.

    The operators and customers have been enormously strained during the past few weeks. We need to rise to the occasion to protect their interests. In my view, the following steps may be taken to deal with the telco fraud-related challenges:

    • Subscriber awareness: A subscriber awareness programme need to be launched immediately to make consumers wary of various fraudulent schemes that are floated during the time of panic and fear. A case in point as reported by one of the Asian operators is that last week many subscribers who had installed the COVID-19 live update apps on their phones coughed up a whopping $ 0.16 Mn because they were unaware that apps would also take over the status of the phone including SMS read and write function.
    • Prioritizing the fraud alerts monitoring: Remote working would have its challenges. The fraud management teams need to prioritize the alerts, especially which would have more impact on the subscribers and act on it and fix them on priority.
    • Root-cause corrective actions: Solution devised to eliminate the causes of fraudulent activity will stem the probabilities of its recurrence. For example, in the network, the range of the high-risk destination numbers may be blocked for a short period if an IRSF fraud attack is detected.
    • Communication and collaboration: We must be connected digitally to all the stakeholders so that they act tough on fraudulent activities on the network. SLA with stakeholders may be refined and suitably tweaked for faster action. This is one of the key elements when the whole team is working remotely to support daily operations.
    • Regular updates on emerging/latest fraud patterns: Frequently visiting the fraud forums to be abreast of the emerging/ latest fraud patterns worked out by the fraudsters. Criminals are always on the lookout to ruin the processes and systems for nefarious ends. Many operators have reported an increase in the robocalls, SMS scam & cyberattack during this period.
    • Making fraud management as part of the Business Continuity Plan (BCP): It is very important to incorporate fraud management as part of the BCP in a major way and ensure we have maximum coverage during this period.

    In my reckoning, the fraud management teams ought to be more vigilant and agile than ever before to meet the new challenges of telecom fraud becoming rife during this global outbreak of COVID-19. Fraud managers are superheroes when it comes to building trust with the customers.

    Stay safe and stay healthy!

    To understand how you can detect and prevent scam and spam calls using advanced machine learning models

    DOWNLOAD THE CASE STUDY

  • How big is the impact of the IRSF Fraud and 5 simple strategies to control IRSF

    How big is the impact of the IRSF Fraud and 5 simple strategies to control IRSF

    International Revenue Share Fraud (IRSF) is one of those fraud types that has been alive for two decades now, all because of the fraud being intricate in its pattern while the approach to it being still very reactive. Here, the motive of the fraudster is to receive the revenue share from the termination charge on international premium numbers. The fraudsters abuse the telecom operator’s infrastructure to artificially inflate traffic onto high-risk international destinations with the intention of non-payment. This fraud is common across geographies and has an estimated fraud loss of USD 5.04 Billion (The highest fraud loss contributor) as per the Communications Fraud Control Association (CFCA) Global Fraud Loss Survey, 2019.

    Lack of adequate steps taken to protect the network has caused this fraud to grow by leaps and bounds. In this fraud, the attacker usually tries to exploit the vulnerabilities of the Telecom Service Provider’s assets and attacks by either calling to unallocated number ranges or land calls onto international premium rated services or illegitimately route calls to short stopped mobiles. Subscription fraud, PBX hacking, Arbitrage Margin, SIM Cloning, Device theft and abuse of promotional services are often the commonly used methods for executing the fraudulent practices. The fraud is also quite common with many fixed line providers.

    In my experience of working with multiple operators, globally, I feel that the most common challenge faced by operators is in understanding the fraud pattern and method used by the attacker. The impact on the operator becomes brutal when fraudsters use unknown patterns of execution and sophisticated techniques to attack the network. IRSF attacks from roaming network, call conferencing, call forwarding, calling cards, negative margin abuse for products and services are among the more popular methods for a fraudster in launching attacks.

    Also, the lack of regulatory precedence in governing the way of carrying out business with international carriers is not sufficiently strict, setting the perfect breeding ground for fraudsters to flourish.

    Why has this fraud grown in leaps and bounds and how do I ensure control proactiveness?

    Traditional and reactive fraud countering mechanisms as of date do not have a full-proof solution, and one of the biggest reasons is that there are not enough fraud controlling strategies, mechanisms, and systems in place. IRSF, unlike other fraud types, requires a continual and proactive measure for control. More than just the “run-of-the-mill” detection techniques, the fraud type requires a well-planned control and mitigation steering strategy and here are six simple strategies, to begin with:

    • Fraudulent practices have become cleverer over time.

    If we brag of the fact that the fraud detection technologies have become quite sophisticated over time, we must not forget that the fraud practices too have gained an equal amount of intelligence. Fraudsters these days are quick to realize technology loopholes and system fault lines. It does not take much for fraudsters today to detect the fraud finding patterns and control logic of CSPs and identify the loophole in the system. In order to counter the fraudster’s attempt of IRSF, study of method and pattern become a critical process. Also use of SIP monitoring technique to identify devices/tool such as SIP vicious can help telcos to prevent IRSF. A mix of AI/ML techniques and models can be used to detect new IRSF fraud patterns with automation and build IRSF intelligence e.g.: trends in calling patterns.

    • Demoralize your IRSF attacker

    Letting your attacker attack you to dig his own grave sounds like an oxymoron? Actually not! It is, in fact, possible to have a honey-trap system in place where you lure the attacker to launch the attacks onto it without a fruitful outcome. The more the attacker’s attempts fail, the less hopeful they strive any further. Additionally, gathering intelligence from trusted suppliers who can provide information about prominent fraud groups and support surgical blocking of international number ranges has proved to be a successful strategy globally to counter IRSF.

    • Think of the customer and protect their interests

    IRSF not just drains away revenue resources but also can cause customer dissatisfaction, causing them to churn out of the network eventually. IRSF not only targets retail accounts but enterprise customer is a key risk group costing the telecom operator millions of dollars. Hence it is crucial that we don’t ignore whenever a customer complains of frequent cross-connections or call diversions for international calls.

    • Have an “Anytime-Anywhere” vigilance strategy with automation to your advantage

    The detection processes for IRSF may be complicated and resource-intensive at times. However, having the right strategies, the right processes with the right amount of automation applied to them can help the business in a significant way. I personally recommend a 24 x 7 detection strategy to be put in place to counter the IRSF attacks. From the cases that I have dealt with, it’s my observation that though IFRS attacks happen round the clock, however, the wee hours of the morning or off-business hours are critical target. Having a rotational manpower strategy can really work wonders at times. However, there could also be instances where having a 24*7 approach may not be possible owing to the lack of capital or high cost of human resources. In such instances, a mix of the automation of detection processes and human intensive operations during crucial hours will be of value.

    • Never ignore negative margins

    Negative margins can occur at any level. It could emerge while planning the pricing strategies of the products, services, use of calling cards in international destinations or interconnect agreements. Feeble margins on profits can often open a pandora’s box for fraudsters. Just the basic knowledge on negative margins is enough for fraudsters to break open mayhem. Trend reports on traffic patterns with priorities given to partnerships with frugal margins can save the day!

    • Pursue strategic knowledge partnerships to establish fraudster intelligence

    Sharing knowledge and having a supportive ecosystem for interaction with carrier partners and vendors in the value chain can be a practical step closer to proactiveness. Also, MoU’s established with industry forums and CoEs like GSMA, CFCA, RAG Blockchain for Wangiri, and others can help CSPs gain information such as PRS test numbers and services, high-risk range numbers, unallocated number series which can be used as vital sources of references to counter this fraud. Telecom operators can also build up the internal defense by establishing service controls e.g. restrictions on the use of international and roaming capabilities for certain customers. And restrict international call forwarding, multi-party calling, etc.

    When I say a reactive approach for AI / ML based IRSF fraud detection, I mean that much of the effort and systems built towards countering the fraud are in silos and so are the human efforts that go into it. By a proactive system, I mean a system that is quite unified in its approach and can perform end to end operations associated with the fraud type. A proactive Fraud Management system shall flag the first call in roaming, track significant deviation in usage behavior, high volumes of international traffic to high-risk destinations, sequential dialing, etc. and couple it with the use of knowledge databases like Subex IRSF data intelligence that includes unallocated number ranges, high-risk ranges, known fraudulent numbers to support network-based blocking and/or integration for early identification of high-risk behaviors and automated blocking, where required.

    One of the many ways of building a more proactive and unified system is to go the AI (Artificial Intelligence) way. A well thought out AI technology strategy can really help detect the fraud at a very early stage and help you choose the right controls for specific problems in question. It aims to reduce the time taken by the laborious human efforts that go into the detection stage while helping analysts and investigators concentrate on the need of the hour. Much as the famous English saying goes “Every cloud has a silver lining,” the impact of the IRSF can considerably be reduced by just broadening the organizational perspectives towards the fraud.

    Subex has recently partnered from Biaas for IRSF data Intelligence, To know how you can benefit from this partnership

    Download the flyer

  • SIM SWAP FRAUD: Stepping into the fraudster’s shoes!

    SIM SWAP FRAUD: Stepping into the fraudster’s shoes!

    “Lose a credit card and the loss may be in thousands… Lose a SIM Card, the loss is irreparable”

    Last week, Twitter CEO Jack Dorsey became the latest high-profile account to be targeted by SIM swappers. Dorsey’s account sent several tweets, including some with racial slurs and others that defended Nazi Germany. Luckily for him, his account was secured soon after, and the consequences weren’t catastrophic. However, there have been many instances where SIM swappers have left victims in a really troubled state – especially the ones targeted for monetary gains.

    SIM swap is a type of phishing fraud that poses a serious threat to customer along with the telecom and the banking environments. The SIM SWAP fraudster in here obtains an individual’s banking details through vishing/smishing/phishing techniques or by purchasing these from organized crime networks. They then use this information, including personal details sourced via social media, to pose as the victim to the mobile network operator and fool them into cancelling and reactivating the victim’s mobile number to a SIM in their possession. As a result, all calls and texts to the victim’s number are routed to the fraudster’s phone, including one-time passwords for banking transactions. After receiving a one-time pin or password from a bank, the fraudster can then potentially access the customer’s bank account and transfer funds. The SIM SWAP fraud impacts not just the victim, financially but also the telecom operator and the bank, equally. As non-adherence to consumer interests and protection, in many countries, both the entities (the telco and the bank) are legally liable to compensate the victim for his/her financial losses. When the loss is in millions, the impact is very grave!

    Have you ever taken a moment to pause and think from a fraudster’s perspective to counter the fraud? Well most blogs that you will find on the internet on SIM SWAP will tell you ways (in bulletin points) as how to protect your assets from the SIM SWAP fraud. However, I am quite sure that there will only be a handful of blogs that will tell you how a SIM SWAP fraudster thinks in-order to be able to protect your customers from such attacks.

    Without much ado, let me take you through the 4 vicious stages involved in the SIM SWAP fraud attack which will help you understand your SIM SWAP fraudster better and stay ahead of them on any given day!

    Stage 1 – “Cherry picking and stalking”

    Fraudsters are always on the loom to pick on their fraudsters and the social media, has, in a great way helped them in getting away with their desired schemes. A SIM SWAP fraudster may look for a high-profile customer or a prosperous and wealthy business personnel who generally solicits with prospective clients over social media. The SIM SWAP fraudster here could impersonate one such client, send out a connection request and start to closely monitor the victim’s activities. The SIM SWAP fraudster can even hijack an account of the victim’s affiliate to initiate conversations/get more information about the victim. In events where the victim does not have enough digital footprints, SIM SWAP fraudsters have even taken the road of dumpster diving and shoulder surfing!

    Stage 2 – “Impersonating the victim”

    At this stage, the fraudster has got all the information he/she needed to pass through the authentication protocols required to get hold of the victim’s assets. Once he/she has managed to convince the bank and Telecom Operator of his/her false identity, he/she goes on to take-over the customer’s personal assets such as his/her sim card or his bank account.

    Stage 3 – “Swindling at once”

    Having gained total control over the victim’s assets, the SIM SWAP fraudster now tries to extract monetary benefits from the victim’s assets at a single go. Here the victim is totally cut-off from his/her mobile network even without knowing it. By the time the victim gets to know that there are transactions carried out on his/her account without their knowledge, the damage is done!

    Stage 4 – “Covering it up”

    After having caused enough damage to the victim, the SIM SWAP fraudster lets go of the victim’s assets and goes on to hunt for another victim. The SIM SWAP fraudster makes sure that he/she makes enough improvisations to his/her fraudulent schemes so as not to appear like a serial offender, thereby leaving the law keeping forces with very little clue of the fraudster’s whereabouts!

    SIM SWAP fraud, unlike many other telecom/bank frauds requires a joint effort from the customer, the bank and the telco. However, catching hold of the SIM SWAP fraudster doesn’t require the brains of Sherlock Holmes! Vigilance and a little proactiveness on how a fraudster might possibly behave can help catch them at a very early stage. To counter the ill-effects of the fraud, top Telecom Service providers like AT&T, T-Mobile, Verizon and other are harping on customer authentication through the 2-Factor method even during telephonic conversations.

    However, I personally believe that not much is being done to study transactional pattern anomalies to identify potential fraudsters in the network and its high time bank authorities joined hands with telcos in countering the fraud. E.g. the telcos can notify the banks of change in a customer’s IMEI/MAC address/addition or modification of accounts/transactional abnormalities and then the banks can monitor the customer’s transactions for that week, in priority! Masking methods can be used during exchange of information to protect consumer interests. Telcos and banks can be more proactive by creating a database for reference where any changes made to the consumer’s profiles can be stored and looked up for instances of abnormal transactions. As preventative measures, customers can be advised by both the telcos and the banks to take enough care while sharing very personal and integral information such as card details, social security number etc. on social media or the public internet.  The SIM Swap fraud is known to cause serious collateral damage and reputational loss, however, a little care taken at the right point in time can work wonders!

    To know more about how you can stay vigilant about SIM Swap fraud, view this video.

  • Account Takeover – Fraudster Intelligence

    Account Takeover – Fraudster Intelligence

    Account takeover fraud is one of the most common fraud types across the world. Fraudsters use the various methods to takeover an existing open account within the mobile operator or the banking instrument. The commonly used method of committing this type of fraud is vishing or smishing. As per CFCA fraud survey, account takeover accounted for an estimated fraud loss of 1.7 Billion US Dollars in the year 2017.

    In all these scenarios, the primary goals of the fraudster are to gain access to the account and (by-) pass the validation steps. In many situations, such validation may only require low-level knowledge-based authentication, so basic information obtained by the fraudster is used to validate and by-pass controls in place and to takeover the targeted account.

    I was investigating an Account takeover fraud case for one of the leading telecom operator in the APAC region wherein the fraudster used a different type of methods to commit this fraud. Many customers lost millions of dollars from their bank accounts without the knowledge after their account was taken over by the fraudster. On investigation, we identified that the fraudster’s primary motive was to takeover both mobile and banking account and then initiate multiple fraud transactions. He used Social Engineering, CLI spoofing, Spoofed website & Malware to commit the fraud.

    The Fraudster sequentially executed his schemes. He targeted only the high-profile subscribers in a region. He acquired all the information of the subscribers using social engineering methodology and called up the subscribers pretending to be a Bank executive and Mobile operator security officer. He asked the subscribers to download a malware-infested application from a spoofed website, following which he gained remote access to their mobile phones.

    The malware would read the SMS’s & call logs from the subscriber’s mobile and forward the details to fraudulent server. It also deleted the SMS & call logs from the mobile handset before the subscriber knew the same. The intention behind the reading of the SMS & Call log is to Bypass the second level authentication for completing the banking transactions. With this method in place, he was able the execute multiple transactions without the knowledge of the subscribers.

    Impact to Telcos?

    When subscribers approached law enforcement agency, the Law penalized both Telco and the bank and recovered from them, the amount lost by the subscriber. The Law took this action to protect the interest of the customers and secondly it was negligence from the service provider that led to the revenue losses of the subscribers.

    Telecom & banking service need to protect the subscribers from such fraud attacks by providing awareness to subscribers. Fraud management systems need have intelligence built into them to detect the fraud attack and control damages at an early stage.

  • Dealing with Bypass Fraud : Think beyond the boundaries

    Dealing with Bypass Fraud : Think beyond the boundaries

    Amid the fierce competition facing the telecom industry, sometimes we listen to stories how lack of forethought of one Telco brings on illegal traffic on the network, leading to aggressive open wars and blame games among the operators affected by the fraud. The Telecom Regulatory Authority could intervene in such scenarios and encourage a competitor to block suspicious outgoing traffic if it finds out that not enough care is being taken to avert the fraud.

    Interconnect Bypass fraud is one such telecom scam costing the industry several billion dollars every year. It brings collateral damage to the networks involved, and the impact will be huge. The Telco could be imposed hefty penalty for its failure to detect and resolve the issue on time. Further, it could bring serious business implications for all participating telcos. In the process of rampant blocking of suspicious traffic, sometimes traffic of genuine customers could get blocked, leading to customer dissonance and dissatisfaction along with loss of other business opportunities.

    Here’s an example of a West African Telco who suffered massively due to Bypass fraud.

    Why did this happen?

    The West African telecom operator had been massively impacted by off-net Bypass fraud where the network of the operator was being misused to land fraudulent calls on the competitor’s network. Over time, the problem became so grave that the Regulatory Authority of the country had to step in and take charge of things. This eventually ended with the competitors blocking both fraudulent and genuine traffic from the Telco affected by the interconnection fraud.

    Investigations conducted confirmed that the huge differences between the International termination rates and local termination rates made the environment suitable for fraudsters to run their schemes. There aren’t enough KYC controls in the country to facilitate certain onboarding checks which distinguish a genuine customer from a fraudulent one.

    Impact on business

    There were multiple warnings and memos issued to the operator from the Regulator, indicating that the operator would have to face penalties if amendments are not made in time.

    Customers flooded the operator with complaints saying that their off-net calls were being barred without prior notice and for no fault of theirs and threatened that they would eventually churn out of the network if their services weren’t restored.

    The atmosphere grew so tense that instead of cooperating, the operators became more aggressive and indulged in a rat-race in trying to prove a point to the Regulator as to how better and efficient they were from the rivals in terms of detecting Bypass fraud cases.

    The solution

    With the understanding that Bypass scams are rampant, Telcos need to direct their efforts towards building knowledge-sharing forums where they can share insights on fraudster behavior and geographical locations from where most of the fraudulent calls are generated and what kind of products tend to get misused by these fraudsters to nip things in the bud.

    Telcos should understand that indulging in rat race or blaming each other will not help solve issues arising from such frauds; rather they should adopt a proactive approach to identify and prevent such scenarios in future. Instead of the Regulatory authority dictating terms to the operators, the operators must drive the authority to create nationalized framework for user identity governance.