Category: Fraud Management

  • Navigating the Treacherous Waters of E-Commerce Fraud: A Call to Action for CSPs

    Navigating the Treacherous Waters of E-Commerce Fraud: A Call to Action for CSPs

    As e-commerce becomes a staple in our digital lives, it brings with it an unwelcome guest: e-commerce fraud. This growing challenge affects millions of online transactions, undermining consumer trust and causing significant financial losses. E-commerce fraud, characterized by deceptive practices such as identity theft and fake transactions, is evolving rapidly in sophistication. In this blog, we delve into the complexities of this issue, highlighting the critical role of Communication Service Providers (CSPs) in combating these digital threats and ensuring a safer online shopping environment.

    The Problem of E-Commerce Fraud

    E-commerce fraud, a pervasive issue in the digital marketplace, manifests through a variety of deceptive practices that manipulate online transactions. This type of fraud ranges from identity theft and unauthorized transactions to intricate phishing scams. The financial impact of e-commerce fraud is alarming. In 2022, retailers missed out on approximately $41 billion due to fraudulent activities, with predictions indicating a disturbing upward trend in the coming years. Its impact is far-reaching, not only causing significant financial losses but also eroding consumer trust and tarnishing the reputations of businesses. This alarming trend underscores the critical need for effective countermeasures to protect both consumers and businesses.

    A Case Study in E-Commerce Fraud: Facebook Marketplace

    The Facebook Marketplace fraud case vividly illustrates the complex nature of e-commerce fraud and the sophisticated methods employed by fraudsters:

    Creation of Multiple Fake Accounts: Fraudsters create several bogus accounts on Facebook, posing as legitimate users. These accounts are then used to list items, typically household electronics and appliances, for sale.

    Listing Items at Attractive Prices: By listing these items at prices well below market value, fraudsters quickly attract potential buyers. This tactic creates a false sense of urgency and an illusion of a great deal.

    Exploiting Trust with a Military Persona: Often posing as military, these scammers exploit the inherent trust and respect typically given to military members, adding a layer of credibility to their scam.

    Demanding Advance Payment Without Delivery: The fraudsters persuade buyers to pay in advance, promising that the items will be delivered subsequently. However, once payment is received, they cut off all communication, leaving the buyer without their money and the item.

    Providing Fabricated Shipping Information: To further the illusion of legitimacy, scammers may provide fake shipping details or tracking numbers, misleading buyers about the delivery status of their purchase.

    Utilizing Phishing Links and Malware: In more nefarious scenarios, scammers may send phishing links or malware disguised as special offers, tricking buyers into revealing personal information or downloading harmful software.

    The underlying mechanism of this type of fraud is the use of the same name across multiple mobile numbers registered under different identities, making it challenging to track and identify the fraudster due to the constant shifting of their identity and contact points.

    The Role of CSPs in Combating E-Commerce Fraud

    CSPs are uniquely positioned to play a critical role in the fight against e-commerce fraud. With their extensive access to network data and technological resources, CSPs have the capability to detect and prevent fraudulent activities before they inflict significant damage. Here are some key strategies that CSPs can employ:

    Social Media Analysis: CSPs can use advanced data analytics to monitor social media platforms. By analyzing patterns of communication and user behavior, they can detect anomalies that may indicate fraudulent activities. This includes identifying suspicious account creation trends, monitoring for messages or posts that match known fraud schemes, and flagging unusual spikes in activity related to e-commerce transactions.

    Blacklisting Fraudulent Points of Activation and Interaction (POA/POI):

    • Points of Activation (POA) refer to the locations or channels where services (like mobile connections or internet services) are activated. Fraudsters often use fake or stolen identities to activate services which are then used for fraudulent activities.
    • Points of Interaction (POI), on the other hand, are the points where customers interact with the service, like making calls, sending messages, or using data.

    CSPs can track and blacklist both POAs and POIs that are identified as being part of fraudulent activities. By doing so, they can disrupt ongoing fraud schemes and prevent the misuse of telecom services for illicit purposes.

    Link-Based and Location-Based Analysis: CSPs can utilize link analysis tools to uncover networks of fraudsters. By examining the connections between different phone numbers, IP addresses, and physical locations, they can identify patterns and clusters of fraudulent activity. Location-based analysis also helps in pinpointing the geographical hotspots of fraud, enabling CSPs to focus their monitoring and countermeasures in these areas more effectively.

    Monitoring for Suspicious Activations: CSPs can focus on monitoring activations, especially from locations known for high rates of fraud. By keeping a vigilant eye on new account activations, SIM swaps, and other telecom activities, CSPs can quickly spot and investigate suspicious patterns. This proactive monitoring helps in early detection of potential fraud rings before they can cause widespread harm.

    Conclusion

    As e-commerce continues to grow, the threat of fraud evolves alongside it. However, through diligent efforts, innovative strategies, and collaboration between stakeholders, including CSPs, e-commerce platforms, and consumers, it is possible to create a more secure online shopping environment. The battle against e-commerce fraud is ongoing, and vigilance is key to safeguarding the interests of all parties in the digital marketplace.

    Step ahead in e-commerce safety

    See our demo in action

  • Harnessing Opportunities and Mitigating Risks in Device Sales

    Harnessing Opportunities and Mitigating Risks in Device Sales

    As telecom operators continually evolve, selling mobile phones and other devices has become a key part of their strategy to enrich customer experience and service offerings. This aspect of the business is not just an add-on; it’s a significant revenue driver, contributing an estimated 12-25% to overall revenues.

    The Double-Edged Sword of Device Sales

    While device sales open up new revenue streams, they also bring forth new challenges, particularly in fraud management. According to the CFCA 2023 Survey, device resale is now a predominant fraud type, contributing to significant losses of approximately $7.4 billion. This alarming trend is indicative of the growing complexity and scale of handset/device fraud. Synthetic Identity Fraud, Credit Muling, and Account Takeover are among the top methods contributing to these losses. The survey also points out that stolen devices often find their way to markets in Asia and South America, and up to 25% of handsets from certain African service providers are fraudulent. Additionally, 1 in 9 applications are reported to be fraudulent, highlighting the need for robust fraud prevention strategies.

    Technological Evolution and Its Implications

    The shift towards 5G and IoT technologies is reshaping the telecom landscape. The advent of 5G is not just about faster speeds; it’s enabling new tech paradigms like Industry 4.0, AI, AR, and VR. This transition is fueling demand for a wider range of devices, including 5G-compatible smartphones, wearables, smart home accessories, and VR goggles. However, with only a third of devices sharing IMEIs with industry aggregators, the risk of fraud in device sales becomes a significant concern.

    A Balance of Vigilance and Innovation with AI/ML Solutions

    In this complex scenario, the need for effective fraud management solutions becomes paramount. AI/ML solutions are at the forefront of this battle, offering the agility, accuracy, and speed necessary to counter these challenges. Embedding AI/ML capabilities into rule-based engines enhances pattern detection and anomaly identification, which are crucial for combating various fraud types. Automation in scrutinizing online transactions and integrating orchestration capabilities for rapid responses are also key strategies in this fight against fraud.

    Subex’s Comprehensive Approach

    Subex’s Fraud Management Solution, leveraging AI/ML, is designed to tackle these challenges head-on. With a hybrid rule engine, enhanced data management, and advanced capabilities like automation, orchestration, and explainable AI, it is well-equipped to help telecom operators navigate the complex landscape of device sales, ensuring legitimate transactions and flagging suspicious ones with precision.

    In summary, the telecom industry is at a pivotal point. With device sales poised for growth, operators must navigate the risks and opportunities with advanced solutions to stay ahead in this dynamic market.

    Protect your device sales revenues with real-time ML based risk scoring

    Request Demo

  • Social Engineering Fraud: A Sophisticated Manipulation in the Digital Age

    Social Engineering Fraud: A Sophisticated Manipulation in the Digital Age

    In the ever-evolving landscape of the digital world, while innovations emerge, so do sophisticated frauds. Despite the advancement in security and digital protective measures, the most glaring vulnerability remains – the human psyche. This is precisely what social engineering fraud capitalizes on.

    Deciphering Social Engineering Fraud

    At its core, social engineering fraud is the art of manipulating individuals into divulging confidential information. Rather than employing traditional hacking methods targeting systems, these fraudsters ‘hack’ human emotions. They exploit our innate tendencies: trust, fear, greed, and the need for urgent action.

    How do they do this? Well, the digital toolkit of a fraudster is extensive. They employ fake phone calls, crafty phishing emails, counterfeit web pages, deceptive chat messages, and even malicious apps. Their mastery lies in impersonation – making you believe they are someone from your family, a trusted bank official, or even a government representative. All these tactics aim for one goal: extracting valuable personal data from you.

    Mechanics of Deception

    The crux of social engineering fraud is the environment of trust. By adopting familiar or authoritative personas, fraudsters place their victims in a comfort zone, only to breach their trust later.

    An exemplary instance is the notorious ‘Jamtara scam’ from India. Here, individuals from the Jamtara district, under the guise of bank officials, would call unsuspecting victims. Using tactics of fear or enticement, they would coerce victims into revealing their banking credentials, resulting in significant financial losses for the individuals targeted.

    Key Features CSPs Should Consider to Counter Social Engineering Frauds

    In the complex arena of social engineering fraud, Communication Service Providers (CSPs) need advanced capabilities that keep pace with evolving threats. As the nature of these frauds becomes increasingly sophisticated, having the right tools becomes essential. Here are some of the features that set the best solutions apart:

    AI/ML: Effective solutions seamlessly integrate both Artificial Intelligence and Machine Learning. This powerful combination proactively identifies unusual patterns and ensures the system is ever-evolving, preempting fraudster tactics.

    Location-Based Analysis: Understanding the origin of potential threats provides invaluable insights. Leading solutions can trace and highlight suspicious activities based on their geographic source.

    Linked-Based Analysis: By harnessing historical data and established patterns, this feature gleans insights based on connections and trends tied to prior fraud markers.

    Modem-Based Equipment Detection: With fraudsters wielding advanced tools, the ability to detect and act against modem-based equipment used in mass attacks becomes indispensable.

    Final Thoughts

    Social engineering fraud represents the convergence of two worlds: the ever-advancing realm of technology and the intricate labyrinth of human psychology. At its core, this type of fraud preys on our innate tendencies to trust and communicate. As our world becomes increasingly interconnected, the pathways for these fraudsters multiply, bringing with it a more considerable threat to our personal and financial security.

    Personal vigilance, while crucial, is only one piece of the puzzle. It’s akin to a sentinel standing guard – always watchful but limited by human constraints. Technological solutions bridge this gap, offering the means to monitor, detect, and act on threats beyond human capacity.

    Leveraging robust solutions like those in Subex’s portfolio becomes not just a choice but a necessity. By harnessing the power of advanced features tailored to counter social engineering fraud, both individuals and businesses stand a better chance in this ongoing digital battle. These tools don’t just act as shields; they become our digital allies, empowering us to navigate the cyber landscape safely, confidently, and proactively.

    Ready to fortify your defenses against Social Engineering Fraud?

    Book a meeting now!

  • How telcos can secure their device sales from fraud

    How telcos can secure their device sales from fraud

    In 2014, an employee at an overnight shipping service somewhere in the US became suspicious about numerous incoming parcels periodically dispatched to two shipping store locations in New York. 

    By 2019, law enforcement stepped in. On opening a box, they found hundreds of mobile phones and several fake IDs. They had unearthed a surreptitious but extremely well-organized mobile phone racket operating across 34 states. 

    The thieves’ modus operandi was to pose as genuine customers (using synthetic IDs) asking to buy or upgrade their phones (with fake credit cards). Upon making a small one-time deposit, they would agree to pay for the purchase in installments. Of course, no payments were ever made. 

    The total loss was a staggering US $19 million – and telecom operators were the most affected as they had to foot the bill.  (Source 1 , 2)

    For many years, telecom operators have been selling mobile phones and other devices to attract subscribers and provide a holistic service experience to their users. Reportedly, this is a rewarding business for telcos, contributing 12-25% to overall revenues.

    But incidents, like the one above, gives a cause for pause. Although device sales are undeniably a revenue opportunity, they come with significant risks.

    Telcos remain optimistic about the profitability of device sales

    Operators are keen to concentrate on this market for many reasons. Firstly, Covid-19 accelerated the sale of smartphones globally as businesses shifted online. Exchanging cash was risky, too, and people preferred to use mobile wallets and touchless payments. Smartphones have become more of a necessity than ever.

    Another strategic industry shift will kindle greater device sales for telecom providers – the era of 5G and IoT. 5G is an enabler of several technology concepts, including Industry 4.0, artificial intelligence, augmented reality (AR), and virtual reality (VR). There is a renewed interest in the devices market owing to the range of devices CSPs can offer to users and enterprises as they launch 5G services. Certainly, smartphone users will be keen to purchase 5G-compatible devices to leverage the value of 5G services, thus increasing device sales for telcos. 5G will also propel innovation in the device market, such as wearables, home accessories and devices, and VR goggles, among others. This expanding range of devices presents telcos with a tremendous revenue opportunity of selling multiple devices to their users.

    But fraudsters also want a share of the pie

    Alongside the promise of this booming growth in the handset market lurks the danger of fraud. The CFCA Fraud Loss Survey Report 2021 lists subscription fraud and account takeover as two of the leading fraud types for telco, both of which are intricately related to device fraud.

    In 2021, telcos lost US $2.03 billion to subscription fraud (where criminals fabricate details to purchase or access goods and services with no intention to pay) and an additional US $1.62 billion from account takeover fraud (where hackers manipulate user accounts to gain access to devices). The Risk & Assurance Group on Risk Assurance and Fraud Management for Communication Service Providers (RAFMCS) capped the losses from handset crime at US $1.87 billion in the same year.

    But what most surveys do not track (for it is extremely difficult to measure) are the indirect losses, i.e., reputational damage, loss of customer trust, and the costs incurred to fight legal battles against fraudsters.

    (To know more about other handset fraud methods, read our paper on ‘Combating Handset Fraud’)

    Unsecure processes have a role to play

    Sales reps are usually motivated by the commissions they earn on device sales, which could result in poor scrutiny of buyer credentials. What’s more, it is easy to exploit the loopholes in digital sales processes and defraud telcos into unknowingly selling their devices to bad actors. And finally, most telcos are still figuring out what kinds of threats to expect with 5G rollouts, as the risk surface across new-age devices is yet unknown.

    Anti-fraud solutions help balance sales, scrutiny, and satisfaction.

    Clearly, telcos ought to employ better scrutiny without compromising the customer experience. Unfortunately, existing fraud solutions lag at providing the needed agility, accuracy, and speed. But this is precisely what AI/ML solutions can augment the solution. Here’s how:

    Embed AI/ML capabilities. Supplement rule-based engines with AI/ML-based capabilities. The AI/ML-based solution should automatically detect patterns and anomalies that cannot be identified manually. These AI/ML-based solutions could have one or multiple models to detect various types of fraud methods/types, thereby providing quicker results for verification at higher accuracy levels without slowing down the customer journey.

    Use automation to deepen scrutiny on online channels. Automatically tap into a wealth of information like personal, biometric, and transaction data to evaluate buyer authenticity. Solutions that encompass AI/ML and deep learning algorithms can correlate such data with finer attributes like email validity to create risk scores, so sales reps can make better decisions on whom they sell to.

    Enable orchestration capabilities for faster responses. To improve efficiency and success rate, the anti-fraud system should have the capability to seamlessly integrate with pointed solutions either by ingesting the dataset into the system or integrating via Rest APIs without any core changes to the fraud management system.

    Indeed, device sales are poised for rapid growth, and telcos that equip their teams with AI/ML solutions can maximize this opportunity, minimize the risk, and win big.

    Subex’s Fraud Management Solution is powered by AI/ML with a hybrid rule engine and includes enhanced data management capabilities, orchestration capabilities, automation, self-serve capabilities and explainable AI. It assists telcos in making the right decisions about legitimate sales and flags suspicious users with unparalleled accuracy.

    Take advantage of new opportunities with confidence

    Reach out to us to know more

  • The False Positive Fallacy in Revenue Assurance and Fraud Management

    The False Positive Fallacy in Revenue Assurance and Fraud Management

    Alex Gendler published an interesting TED-Ed video on the false-positive paradox. He narrates a hypothetical scenario where a precious metal ‘unobtainium,’ present within only 1% of rocks in a specific quarry, must be mined. Joe, the miner, uses a reading device to identify which rocks contain the precious metal. His device will always detect unobtanium when present. It will also give the correct reading 90% of the time when a rock does not contain unobtanium. Now say Joe’s device beeps when pointed to a rock, and he offers to sell it to you for $200. Is it worth buying this rock from Joe for $200, knowing that you can sell an unobtanium rock for $1000, based on the reading of the detection device?

    To determine the answer to this question, it is imperative to note how rare the presence of unobtanium is as well as the 10% likelihood of false positives from the reading device.

    Any anomaly detection test or model that is not 100% accurate bears the risk of false negatives and false positives. In the revenue assurance and fraud management (RAFM) domain, the presence of false positives can be tricky as it utilizes resources to investigate that the anomaly is, in fact, not a problem.

    Like Gendler’s scenario, one fundamental point to remember is that revenue leakage within revenue assurance and fraud management departments is quite rare. But since nearly 75% of operators report at least 1% leakage of the total revenue, false positives warrant some investigation.

    What would be the successful formula for investing in a system that identifies rare leakages or fraud, especially when false positives abound? 

    Here are some key elements to look out for:

    1.  Calculating ROI 

    Any well-designed revenue assurance and fraud management strategy must articulate short-term as well as long-term benefits. But as time passes, software/controls age, become redundant, or lose their effectiveness. Moreover, it is seen that as operator maturity increases, leakages decrease and, hence, the probability of identifying these leakages.

    Recommendations:

    From a practical perspective, operators need updated solutions to adapt flexibly to changing scenarios such as new revenue streams and broader risk coverage.

    Each solution should encompass well-defined KPIs to measure not only the intended output of revenue assurance and fraud management (like the number of subscribers impacted and revenue at risk) but also its quality (like the effectiveness of a revenue assurance and fraud management control).

    2. Choosing controls

    The process of designing a ‘control’ or a ‘check’ is the key to minimizing the hassle of false positives. Revenue assurance and fraud management teams often struggle to manage the reference data, data specifications, connectivity, latency, etc. All data management parameters can influence false positives and, thus, require timely correction. Since all control systems are not equal, arriving at an effective control design (including the alarm thresholds) is challenging.

    Recommendations: 

    Establish key indicators to measure system performance for business outcomes as well as revenue assurance and fraud management processes.

    Track support processes on overall outcomes to avoid unwanted influences on the quality of revenue assurance and fraud management controls.

    Streamline processes through artificial intelligence (AI) and machine learning (ML) to correlate different outcomes and reduce the number of false positives. To understand the significance of this, even low levels of false positives compromise the ability to detect genuine leakages.

    3. Maintaining accuracy

    The probability of finding a genuine alarm in the revenue assurance and fraud management system indicates how much effort is needed to identify leakages. It also signals the number of alarms that will be closed as ‘non-fraud.’ False positives are usually measured from the system’s perspective, i.e., how many false alarms exist out of the total alarms generated? But most systems do not reflect the actual effort involved in getting the expected benefits of the control.

    Recommendations:

    Identify the potential trade-offs between implementing a control, its benefits, and its costs. The cost is mostly understood as a development effort but should also include maintenance and monitoring effort.

    Consider each control in the broader context of the overarching control framework and risk coverage. This may unearth risks that are over-controlled or under-controlled, thereby suggesting areas that need improvement.

    4. Easy monitoring 

    When the probability of identifying a genuine fraud attempt or revenue leak decreases, the monitoring effort increases because more alarms and controls will need to be set to identify the incident.

    Recommendations: 

    • AI and ML can quickly identify false positives, determine likelihoods, and present these to analysts for immediate action.
    • Revenue assurance managers can save time spent on investigating cases that are not leakages. For fraud management leaders, it helps avoid customer discontent when cases are not fraudulent.

    Dealing with the uncertainty of false positives is a painstaking exercise. By implementing the right controls and tweaking these systematically, revenue assurance and fraud management teams can maximize the return on investments of their monitoring systems.

    (The answer to the unobtainium question is: No. Statistically, the buyer has only a 9% chance of finding unobtainium in the rock, which is pretty poor odds that the $200 investment will pay off!)

    In your experience, what best-practices help deal with false positives?

    On-demand Webinar: AI Master Class for Fraud Management

    Watch Now

  • In a conversation with GO Malta about Fighting CLI Spoofing

    In a conversation with GO Malta about Fighting CLI Spoofing

    Voice over Internet Protocol (VoIP) networks are extremely popular for their ability to save costs, support innovations like 5G, and roll out features such as video calling. With the workforce becoming increasingly distributed,businesses and customers want affordable international calling plans that support mobility. Some estimate that the VoIP market will reach US $30 billion by 2025.

    However, IP networks have vulnerabilities that expose them to risk.

    Arvind Rao, Director of Business Solutions Consulting at Subex Limited, and Charmaine Galea Triganze, Fraud Prevention Officer at GO (Malta), recently presented at the CFCA Educational event, where they discussed the problem of CLI Spoofing at GO. According to Arvind, “VoIP-based attacks constitute roughly 45% of all fraud security events today, as per the recent CFCA report. In fact, out of the top 10 fraud methods recorded by CFCA, 6 of them are related to VoIP-based attacks.”

    (In case you missed the event, the conversation below offers the main highlights.)

    To provide a context of what was happening at GO, Charmaine recalls, “We were getting reports from broadband customers, internal employees, retail customers, and business customers that something wasn’t right. Someone would receive a call that originated from Italy, an EU country, but it would be their relative based out of Canada or Australia. As these reports increased, we started investigating the CDRs in our existing fraud management solution, and the data was conflicting, showing the number was from Italy or any other EU country. That was when we called Subex to do a proof of concept. What we found was quite alarming.”

    Since the EU works on an origin-based rating, rogue carriers were exploiting a loophole to pay lower terminating charges. As the investigation deepened, more concerns surfaced. Caller ID spoofing was wreaking havoc: Scam calls had increased during the pandemic. Scamsters began spoofing numbers of well-known businesses in Malta. Customers, trusting of EU numbers, were prone to pick up these calls. Apart from being a nuisance to retail customers, it created immense ecosystem challenges.

    GO collaborates with law enforcement to aid criminal investigations by providing information about a suspect’s call records or location. However, in many cases, the data passed on from CDRs turned out to be incorrect. Charmaine states, “The police would complain, stating they asked for a specific person’s records but based on the data we shared, it was implausible that the suspect made these calls from the number provided.” It was compromising the operator’s reliability.

    One of the most telling stories Charmaine narrates was how spoofed numbers were disrupting Malta’s emergency services. “People would call emergency services, request assistance, and hang up. On tracing the call, emergency services would be dispatched to the location only to find confused people wondering why the police were at their door! You can understand that the emergency department was not happy. They repeatedly asked us to stop the spoofed calls or at least sieve out the genuine ones from spoofed numbers so they would know which to ignore and which to respond to. But the existing system was not able to give us this information.”

    Modern problems need modern solutions

    Arvind explains why, “Traditional fraud management systems which are reactive, transaction-based and rely entirely on call detailed records, are not best suited for addressing these VoIP based frauds in real-time.”

    To visualize this, let’s consider the standard OSI stack starting from Layer 1 to Layer 7 and walk through what happens during a CLI spoofing attack.

    CLI spoofing attacks typically begin with a port scan at Layer 3, wherein a program looks to identify what services are running on the network. Once discovered, probing or brute force attacks ensue, after which the attack moves to the application layer or layer 7. “This is where we start seeing breaches,” says Arvind. “However, many lower-level attacks and failed attacks are not monitored, as no records or transactions are generated. Thus, traditional fraud management won’t kick in. Moreover, such systems do not track these failed attempts.”

    “Here is where Signaling Risk Intelligence systems make a difference,” adds Arvind. ” A robust signaling-based detection and prevention system monitors signaling information across the layers and look for malicious behavior. From a technical aspect, they observe network packet captures, usually using port mirroring in a non-intrusive manner, without causing any network lag. Using shallow and/or deep packet inspections to identify markers or threat signatures like SIPvicious software as the user-agent. Apply other detection measures such as heuristics-based detection and look for a relationship between A and B numbers, including looking for calls made or from unallocated numbers.”

    The issue of unallocated numbers is an important marker of fraud as this highlights a behavior wherein the random dialer/program showcases malicious behavior.

    Put into the mix of using an AI/ML-based approach for further identifying hidden correlations and patterns, a robust solution can be deployed. In fact, such a trifecta approach was enabled by Subex at Go Malta to address the CLI spoofing fraud.

    A host of benefits

    Charmaine is glad because since implementing Subex’s signaling security solution, GO can stop calls directed to unallocated numbers. “We started charging the highest terminating rates for calls to unallocated numbers from partner carriers, and soon, this practice reduced drastically, saving us revenue.”

    The solution also performs several other tasks, such as analyzing error codes and using advanced AI/ML to analyze dialing patterns and identify spikes in traffic using anomaly detection. “We didn’t know much about monitoring signaling traffic, but Subex provided us with the right training to understand SIP signaling,” she declares.

    Subex’s extensive (the world’s largest) honeypot network is an added advantage. It provides threat intelligence from external databases and has a repository of over 55,000 different malicious signatures and more than 8,000 malicious IP addresses to give operators an edge in addressing technical frauds.

    Insights from the solution are also helping Go Malta do other things apart from improving assistance to law enforcement agencies and protecting its customer from spoofed calls. Charmaine notes, “Our business clients were using international platforms, so we found a way to offer them local solutions, which gave us more revenue while helping them save costs.” Customer satisfaction, a foundational lever at GO, has also risen because customers are duly informed when a number is spoofed.

    Follow the money

    Can a signaling-based defense mechanism give operators a leg up on dealing with new-age frauds?

    “Absolutely!” asserts Arvind. “It ticks off the three main goals for fraud management, i.e., to widen fraud coverage, reduce fraud run-time, and improve the fraud hit ratio.”

    Malta is already leveraging the much-needed boost. Recently, the commissioner of police set up a task force between three major operators in Malta (including GO), banks, and postal services. Charmaine opines, “There is no single way to fight fraud. CLI spoofing affects all of us because people are lured into disclosing financial information, affecting banks too. Only through ecosystem cooperation can we make sure that fraudsters don’t make a financial profit.”

    Warmly referring to GO’s anti-fraud solutions as ‘her toys,’ Charmaine quips, “As I say, ‘Follow the money. The more toys we have, the better we can track the fraudsters, and the stronger our defense!”

    Meet our experts to discover the features of Subex’s Signaling Security Solution.

    Schedule a meeting!

  • How CSPs can monitor and monetise flash calls

    How CSPs can monitor and monetise flash calls

    As seen in Vanilla Plus

    When accessing personal information or conducting an online transaction, a One Time Password (OTP) is typically all that’s required to verify your identity. Although OTPs provide an extra layer of security, issues do arise.

    Bad actors are using phishing scams to gain access to OTPs at an increasing rate. And, with OTP interception services available on the dark web, even novice fraudsters are successfully circumventing the added security. In addition to serious security concerns, SMS OTP two-factor authentication (2FA) process falls short in other areas, like customer experience. For instance, once a user enters their phone number, they must wait for the code to arrive. Sometimes it never arrives. These issues, along with the rising costs for businesses to send 2FA SMS messages, have accelerated the need for an alternative authentication method.

    Will OTP vanish in a flash?

    For businesses and communications service providers (CSPs), ‘flash call’ verification is rapidly becoming the preferred alternative to OTP 2FA. Juniper Research defines flash calling as” an authentication process that leverages mobile networks to authenticate users or actions. “

    Juniper Research predicts that the number of flash calls used for authentication will increase from 60 million in 2021 to 5 billion in 2022. A longer view forecast, also by Juniper Research, estimates that flash calls will reach an incredible 128 billion calls by 2026, which equates to a compound annual growth rate (CAGR) of 128%.

    This unprecedented growth can, in part, be attributed to its processing advantages. Basically, the system places a call to a number provided by the user. The user’s profile is then verified by authenticating the last few digits (usually 4 – 6 digits) of their phone number. While in most cases, the user isn’t required to do anything, sometimes flash calling requires the user’s interaction, such as selecting an icon or entering a password or passcode.

    From the perspective of a business, flash calling is swift, cost-effective, provides additional security, and has fast application programming interface (API) integration. From a user’s perspective, it delivers a nearly seamless customer experience. However, with the exponential adoption of flash calling, CSPs need to look at the monetisation opportunities it can provide.

    How will flash calling impact CSPs?

    This year alone, it is expected that authentication-based messaging will generate $39 billion in revenue for mobile operators. However, as an increasing number of companies begin to migrate authentication traffic to voice, flash calls have the potential to wreak havoc on operators’ SMS revenues.

    Another foreseeable headwind that service providers need to prepare for is increased competition from Over the Top (OTT) messaging app companies that provide alternative mobile network operator (MNO) messaging services. Historically, CSPs have lagged OTT players when it comes to implementing new services. On the other hand, OTT players have made their mark by being quick to identify market trends and pivoting in quickly to cater to changing consumer demands. For instance, OTT player WhatsApp has already announced its flash calling intentions and is working on integrating it within their applications, giving them a head start in meeting market demand.

    OTT players entering the flash market also face challenges. There have been reports of users losing access to their accounts, such as what happened to WhatsApp users when they shared their verification codes with someone claiming to be from the company.

    How can flash calls give CSPs a new revenue stream?

    Service Providers will need to move quickly to begin monetising flash calls. However, in most cases, they do not currently have the technology needed, which results in their inability to monetise the service. For operators to capture this revenue stream, they will need to implement cutting-edge technology that will enable them to detect and validate flash traffic, as well as detect and protect against suspicious behavior.

    For service providers to protect their Application to Person (A2P) revenue stream, solutions such as real-time fraud management systems, complex machine learning (ML) algorithms, and pattern mining tools will be essential. End-to-end fraud management solutions that provide 360-degree protection will also be essential. These solutions typically leverage artificial intelligence (AI) at every step of the process to effectively combat fraud and security risks. When capabilities such as statistical analysis, feature algorithms, auto ML, and data preparation are included, operators gain superior fraud protection over their OTT competitors.

    Data pattern mining tools are another crucial component needed to detect evolving fraud patterns. This is made possible with enhanced rule modeling capabilities that can be configured to incorporate threshold, geographic, pattern, hotlist, spam detection, intrusion detection, and smart pattern rules.

    From a revenue perspective, Juniper Research recommends that operators look at mirroring the business models of established A2P SMS market leaders. Their monetisation models almost exclusively rely on charging on a per-traffic basis. Adopting this model will enable operators to increase flash calling adoption, as well as revenues. While monetising flash calls comes with its challenges, the potential financial benefits far outweigh those challenges. But to overcome the head start of OTT players, service providers will need to move quickly.

    One stop solution to address all types of telecom frauds across Voice, Data and Digital Services

    Request Demo

  • The AI-First Approach to Fraud Detection and Prevention

    The AI-First Approach to Fraud Detection and Prevention

    As seen in Pipeline Publication

    Fraud is a persistent nuisance for communications service providers (CSPs) across the globe, and unfortunately it just continues to grow in intensity.

    The increasing use of sophisticated technologies by the fraudsters has resulted in a surge in the frequency as well as the intensity of telecom frauds. CSPs’ digital transformation and the ever-increasing pervasiveness of the digital economy have only made it worse. The growing 5G ecosystem now is likely to make CSPs’ ongoing battle with fraud even more important.

    According to Communications Fraud Control Association’s (CFCA) Fraud Loss Survey Report, 2021, the total telecom revenue loss due to fraud is estimated to be 2.22 percent of total revenue, or $39.89 billion. What is more worrying is that there has been a 28 percent increase in fraud losses when compared to 2019. Apart from revenue loss, fraud also results in loss of reputation and potentially even subscribers for CSPs.

    The traditional rule-based fraud management systems are not enough to address the growing sophistication, frequency, and ferocity of telecom frauds, thus making it imperative for CSPs to rethink their fraud management measures and strategy.

    Fraudsters’ tactics have evolved over the years as the traffic on the communications networks continues to grow. The obsolete risk management systems are hardly geared to prevent or detect fraud. As a result, it has become more challenging for CSPs to detect fraud even as losses continue to mount for telcos in all geographies.

    The growing sophistication of the fraudsters means that CSPs, who continue to use older and traditional fraud management systems, are on the back foot and are always trying to catch up with the modern methods used by the fraudsters.

    CSPs can no longer depend on traditional fraud management systems because fraudsters are using innovative technologies to conduct fraud. In a way, fraudsters are taking advantage of the gaps in the weak and redundant traditional fraud management system to conduct frauds blatantly.

    A key issue CSPs face is that the traditional rule-based fraud management systems are reactive in nature. This can be particularly problematic considering that 5G will significantly expand the number of protocols, applications, systems, and endpoints, leading to enhanced risks. It’s imperative that with faster cloud adoption and a growing 5G ecosystem, fraud management needs to transform to be preventative and proactive.

    Increasing technology and process complexity 

    One of the key reasons CSPs continue to struggle to catch up with the growing crimes is the increasing network complexity because of new technologies and the ever-increasing number of services they offer. Telecom service providers are no longer offering just vanilla voice and data connectivity. Mobile money and other fintech products, educational products, and gaming are just some of the new services provided by the telecom service providers. Furthermore, several service providers have started offering 5G-enabled augmented reality (AR), virtual reality (VR), and Industry 4.0 use cases. All this leads to a massive change in how telco business and operations are managed.

    The operations are further complicated by the emergence of new business models, such as partner-led business models, API-led business models, compute-led business models, subscription-led business models and use-case-led business models, making traditional fraud systems deficient. The new use cases and business models will require integration with different types of platforms in which they are not just monitoring or evaluating data but also need to respond in real time.

    In the 5G era, CSPs will need to collate and manage data in real time from several sources to proactively mitigate risks, thus making it critical to revamp their fraud management strategy. In addition, 5G will enable a greater number of deployed devices, which unfortunately provide a larger attack surface for fraudsters using Internet of Things (IoT) devices. According to CFCA Fraud Loss Survey Report 2021, 32 percent of CSPs expect to see an  increase in 5G fraud because of protocols and the number of connected devices. The manual processes are not designed to manage the growing volume, variety, and velocity of data likely to be generated in the 5G era. According to OpenSignal, 5G users consume 2.7 times more data than 4G users.

    As the services offered by telcos grow, the CSP partner ecosystem also records an increase. The growing ecosystem of the Internet of Things (IoT) especially poses a challenge for CSPs, as it brings to the fore different types of devices, partners, and service providers on one platform, thereby providing newer avenues for fraudsters to access the system. One weak link is enough for fraudsters to carry out a massive scam, significantly impacting CSPs’ profitability.

    Growing skill challenge

    Faster adoption of the cloud and the growing 5G ecosystem mean that the risk management teams require new capabilities to deal with risks posed by new technologies and use cases that cut across several products and services.

    CSPs’ risk management teams need to be agile to continuously handle changes in the business. The teams should also have the ability to perform different data operations such as statistical analysis, behavioral analysis, protocol analysis, predictive analysis, and so on to capture risk-based insights from the data.

    There is a greater need to upskill and increase data literacy within CSPs’ risk management teams. This is crucial to gain the ability to deal with newer forms of data sets to address the evolving type of fraud—and also to ensure the successful implementation of risk mechanisms.

    A key challenge faced by risk management teams, however, is the skills shortage. According to the Risk & Assurance Group 2021 Digital Trust Survey, finding skilled people is one of the critical challenges faced by CSPs in addressing growing fraud. This is likely to further grow with the 5G ecosystem, leading to an increase in the demand for these skills.

    CSPs can partly address these challenges by using AI-powered automation. It is critical for the risk management teams to quickly scale up, enhance coverage and bring down the dependency on manual labor. This will also increase operational efficiency while freeing up resources for more strategic work.

    Addressing new-age fraud with an AI-first approach

    Amid growing fraud losses and the emergence of new challenges, CSPs stand to benefit by leveraging the capabilities of artificial intelligence (AI) and machine learning (ML) based systems to gain the required efficiencies to address new-age fraud. AI and ML hold tremendous potential for CSPs to not only bring down fraud-related losses but also to enhance the trust of their subscribers in their infrastructure.

    An AI-powered fraud management system comes with capabilities to quickly identify and respond to suspicious activity. It can combine data, both structured and unstructured, from several data streams and make sense of it in real time to help telcos efficiently stop fraud before it negatively impacts their revenue and reputation.

    In addition, AI and ML will be key proponents for handling changes in business scenarios and enabling risk management teams to be more agile. Another key advantage of an AI-based system is that it can collate both structured and unstructured data from multiple sources such as Kafka, pub-sub, APIs, and more, leading to faster detection of fraud and minimizing fraud run time.

    Also, CSPs can further leverage AI and ML capabilities to make informed decisions if it is explainable, meaning that it provides complete clarity and visibility on how decisions are taken. Therefore, a fraud management system based on Explainable AI eliminates AI bias completely and provides transparency on how decisions are made.

    Despite the potential, however, adoption of AI/ML-based fraud systems continues to be low. As per the CFCA Fraud Loss Survey Report 2021, 30 percent of the respondents are still using manual processes, while 28 percent use rules-based fraud management systems, and only 13 percent are leveraging AI and ML-based fraud management systems. The increasing sophistication of the frauds committed underlines that the methods being used by CSPs are not sufficient. Therefore, CSPs must adopt an AI-based approach to bring down fraud-related revenue loss.

    The growing fraud losses of telcos coupled with the increasing level of sophistication of fraudsters means that CSPs must reexamine their fraud management strategy. It is time to adopt AI-first fraud management systems that use the latest technologies for both prevention and quick detection of fraud, thereby taking a more proactive—rather than reactive—approach to risk mitigation.

    Explore the Use Cases and Strategies for Combating Frauds with Advanced Analytics and Machine Learning

    Request Demo

  • Combating AIT Fraud with AI: Strategies for Success

    Combating AIT Fraud with AI: Strategies for Success

    Introduction  

    The telecom industry is projected to reach $4.16 trillion, with a Compounded Annual Growth Rate (CAGR) of 6.35% (1), in a significantly mature marketplace. A recent survey of telecom losses puts the figure at a whopping 2.2% of the current market size of $1.8 trillion. An increase of 28% from 2019. Among telecom frauds, AIT fraud has been on the rise since many Mobile Network Operators (MNOs) have not invested sufficiently in preventing Artificially Inflated Traffic (AIT) and Artificially Generated Traffic (AGT). AIT (which includes AGT) results in tremendous losses to both operators, and according to Forbes, this figure has grown 600% in the past 10 years to $10.76 billion (2).

    So, who gets affected? Both user and operator. So, who is accountable? Also, both user and operator. So, how do we prevent it?

    What is AIT fraud? What constitutes AIT fraud, how it works, and what effect it has?   

    Before we look at ways to prevent it, let us first look at what AIT is and the different types and causes of AIT fraud. AIT usually begins with the name itself – Artificially Inflated Traffic. The fraud perpetrators start by triggering avoidable and often unnecessary calls, SMS text messages, One-Time-Passwords (OTP), and other MNO services that either cost the customer or the operator.

    How it works is that when the user’s mobile phone makes calls, sends a message, or triggers the receipt of a message, it triggers the accounting workflows between the user’s MNO and the target MNO. The target MNO in this case, is usually one with high termination fees. Since termination fees are revenue streams for MNOs, the fraud perpetrators can benefit from a revenue-sharing agreement with the target MNO who may be completely unaware of the unscrupulous nature of the traffic generated.

    AIT often escalates into other types of fraud, including hacking, phishing scams, and identity theft, where the victim’s mobile phone can be used to create Artificially Inflated Traffic in the form of calls to high-termination MNOs, but also result in fake numbers, and a multitude of possibilities that perpetrators can exploit with ease. Another significant source of AIT fraud is when the Caller Line Identification (CLI) is spoofed to prevent the receiving MNO from identifying the source of the call, thus taking unfair advantage of the difference in termination rates.

    The losses to operators, compounded with churn, regulatory intervention, significant loss of credibility, etc., have serious repercussions which require immediate action.

    Detection& Prevention of AIT fraud

    Having delved into how AIT fraud is perpetrated, there are ways to detect, reduce, mitigate, and prevent AIT fraud, but these are not simple. Preventing and reducing AIT fraud requires the use of the right set of tools and technologies, along with a consistent and conscious approach from both the operator and the user. Let us look at some of the ways to combat this fraud:

    Analytics and AI: Analyzing traffic, identifying patterns, and automating responses based on historical data are crucial to ensuring a progressively increasing number of AIT frauds are eliminated before it enters the network. Some of these methods include:

    1. Pattern Detection: AI can analyze traffic patterns and detect anomalies in data much faster and more accurately than humans. By using machine learning algorithms, AI can detect traffic patterns that are artificially inflated and alert authorities.
    2. Real-Time Monitoring: AI can monitor traffic in real time and detect any suspicious activities. This can help prevent artificially inflated traffic fraud before it happens.
    3. Analytics: AI can use predictive analytics to detect traffic patterns that may indicate artificially inflated traffic. By analyzing historical data, AI can predict when a website may experience artificially inflated traffic and take action to prevent it.
    4. Behavioral Analysis: AI can analyze user behavior to detect whether the traffic is real or artificially inflated. By analyzing factors such as user location, browsing history, and click patterns, AI can identify whether the traffic is from real users or bots.

    Monitoring: Whether at the operator level or the user, monitoring of calls, messages, and other network activities at the network level and the user’s device is crucial to identify potential AIT fraud instances. From simply blocking typical calls and messages originating from fake numbers to reporting spam, regular anti-malware scans can help users prevent losses to themselves as well as the network operator. Likewise, operators can use network scanning and monitoring tools to identify the AIT and devise approaches to mitigate AIT fraud.

    Vigilance: While the technology component – firewalls, monitoring tools, and AI can significantly improve the efficiency of AIT fraud reduction, the users also have to assume responsibility for the traffic that they experience on their devices. Refraining from installing apps without verifying their authenticity, and avoiding circumventing content restrictions, as these are significantly large sources of AIT in the form of spam calls and text messages, and fraudulent apps, which may, in turn, result in spam, as well as OTP fraud, phishing, and other potential causes for losses both for the user and the operator.

    Conclusion:  

    As much as our technology solutions improve in their ability to detect and prevent AIT fraud, they cannot all be eliminated in one fell swoop. And until it becomes untenable for the perpetrators, it is up to users and operators alike to remain cautious and vigilant and keep updating their understanding of how, why, and what perpetrators of AIT do to achieve their goals.

    References: 

    1. https://www.skyquestt.com/report/telecommunication-market
    2. https://www.telecomreviewasia.com/index.php/news/featured-articles/3124-a2p-sms-fraud-a-rising-threat

    Explore the Use Cases and Strategies for Combating Frauds with Advanced Analytics and Machine Learning

    Request Demo

  • Telcos must do more than just shake off SMS fraud

    Telcos must do more than just shake off SMS fraud

    A telco we recently spoke to narrated how scam SMSes were creating trouble for its subscribers, but its risk team was able to ‘shake it off for now. Interesting choice of words: ‘shake it off, a phrase popularized by Grammy Award Winner, Taylor Swift, who has been busy shaking off other things like a record deal that turned sour last year, driving her to re-record her first 6 albums.

    Unfortunately, unlike the pain of past relationships, which is what the singer croons about in her chart-topping hit, SMS fraud isn’t something that can be easily shaken off by telcos.

    Sending the right message

    A text message from a friend is a person-to-person or P2P message. A message from your bank sharing an OTP is an application-to-person or A2P message. A2P SMS finds use in areas like two-factor authentication, sharing details about bookings, reminders for appointments and travel, updates about deliveries, notifications about discounts, sales, and promotions, etc., making it an indispensable information delivery channel. Since the pandemic, the number of A2P SMSes traveling across telecom networks has shot up. It is estimated that 3.5 trillion A2P messages will be sent in 2023, marking a 40% increase over 5 years. On the other hand, the flourishing of OTT apps providing free messages has put a dent in P2P messaging revenues. Nevertheless, subscribers consider SMS a safe channel of communication. A study on marketing channels reveals that the average open rate of a marketing SMS is 99% compared to 28-33% for marketing emails.

    What goes on behind that SMS

    Convenience is perhaps the best thing about sending a text message. It’s quick and does what it is supposed to. But there is a whole machinery at play to ensure that every ‘send’ button clicked on an SMS creates revenue for telecom operators and many, many intermediaries.

    The SMS ecosystem consists of numerous players supporting the business of P2P and A2P SMS. There are SMS resellers, SMS hubs, Rich Communication Service (RCS) providers, and SMS aggregators, to name a few. The infrastructure also comprises several components like SMS centers as well as software such as SMS gateways and SMS APIs. Each of these plays a role within authorized routes, allowing messages to be delivered from a business through an MNO to the right customer.

    SMS resellers provide software that allows quick broadcasting of business SMSes based on an agenda with pre-built templates. SMS hubs streamline the flow of international SMS through interoperable systems between telecom operators, enabling wider reach at a lower cost without complex agreements. SMS aggregators are niche telcos that act as intermediaries between many MNOs to send and receive SMS connecting brands to their customers. SMS gateway is a website that allows businesses to send bulk SMSes to their customers via telecom networks and supports international SMS. And finally, SMS API, a new addition to the market, is a piece of code that dispatches SMS via an SMS gateway and also supports text message communication between different web applications.

    Understanding ‘The Blank Space’ of fraud 

    Interactions between these nodes and players are complex and governed by numerous and verbose contracts outlining cost, frequency, carriers involved, interruptions, disputes, privacy, and much more. But fraudsters commit much time to find loopholes within networks and agreements that they can exploit, such as weaknesses within SS7 signaling protocols and grey routes. According to CFCA Fraud Loss Survey 2021, SMS fraud accounts for US $3.65 billion in losses.

    Here are some well-known fraud types:

    • SMS Spoofing – The location and identity of the sender are spoofed to mimic a known business
    • SMS Faking – Signaling parameters are manipulated to fake the operator’s details, causing customers to receive unsolicited SMS
    • SMS Spamming – SMS is embedded with a callback premium rate number, incurring high charges
    • SMS Malware – Hackers breach MNO systems to steal sensitive user information
    • SMS Bypass – Traffic is routed through alternate networks and grey routes, leading to a loss of revenue for telco
    • SIM Farms – A collection of SIM cards are used to issue business SMS to avoid paying enterprise SMS rates

    SMS fraud creates much harm. It leads to identity theft, financial theft, and network manipulation. It significantly erodes customer trust in the primary communication channel. For example, nearly 64% of customers worldwide are concerned that mobile messages could be from impersonators trying to steal their data, money, or identity.

    And they are right to be concerned. Today, a majority of SMS fraud remains undetected. It affects operators through the leakage of SMS revenue and negative brand image. Businesses cannot monetize their services as people become distrustful of promotions and sales discounts.

    Re-orienting fraud and security solutions for the new age 

    Telcos need a diverse ecosystem of SMS players to forge international connections between people and businesses. However, they ought to focus on transparency and weeding out misaligned players if they want to secure their SMS ecosystems and sustain revenues from A2P and P2P SMS.

    SMS firewalls are among the most popular approaches, but their efficacy is waning in light of emerging SMS threats due to new signaling protocols. Techniques such as real-time signaling analytics, heuristics, and advanced ML techniques give all parties – businesses, operators, and users – visibility into SMS interactions so operators can identify any SMS fraud. As operators re-orient their security systems to fight SMS fraud, it fosters customer confidence, secures access from businesses to their consumers, and creates a thriving ecosystem for genuine players.

    Perhaps it is time for telcos to move from merely ‘shaking off fraud’ to ‘knowing that it’s trouble’ and adopt a long-term view to combat it. They ought to upgrade their fraud management system to mitigate any form of risk proactively.

    Subex’s AI-first Fraud Management Solution provides a data analytics platform that helps CSPs engineer ML features, leverage a global honeypot network to spot anomalies faster, identify malware attacks in SMS, and ensure real-time SMS threat monitoring.

    To see how our signaling to fraud management solution telcos from SMS fraud

    Connect with a Subex expert now!