Category: Fraud Management

  • Lessons from a Spy: How 007 is Helping Telecom Industry Fight Robocalling Fraud

    Lessons from a Spy: How 007 is Helping Telecom Industry Fight Robocalling Fraud

    In the iconic spy world brought to us through the imagination of Ian Fleming, I’ve found the array of gadgets almost as thrilling as the action sequences. Remember the invisible car in ‘Die Another Day’ and how James Bond was able to control it remotely. A little out of whack, right? But that was 20 years ago. One look at today’s autonomous cars, and somehow that level of innovation doesn’t seem so implausible anymore.

    Here’s another less known fact: In the time it has taken you to read this, nearly 55,000 robocalls have made its ways to phone numbers across the globe. Robocalls are automatically dialed telemarketing calls that play pre-recorded ads and promote products. Sounds harmless, right? Not always. In many cases, robocalling acts as a gateway to scam people out of millions of dollars, mostly through CLI spoofing.

    According to research, robocall fraud may cost consumers US $40 billion globally by 2022.

    Shaken, not stirred: A cocktail of safeguards

    In 2019, the Federal Communications Commission was called in to help. They came up with the Secure Telephone Identity Revisited (STIR) and Signature-based Handling of Asserted information using toKENs, also known as the STIR/SHAKEN framework.

    Admittedly, the FCC had to do a lot of head-scratching to come up with a name that would render the acronym STIR/SHAKEN. If the acronym sounds familiar, it is because it was inspired by secret agent 007 James Bond himself who famously prefers his Martinis shaken, not stirred.

    STIR/SHAKEN is a set of rules, protocols, and procedures designed to enhance call integrity through authenticating caller ID information by assigning each call with an encrypted digital fingerprint, enabling receivers to tell an illegally spoofed call from a legitimate one. In March 2020, the framework became a mandate for all CSPs to follow to curb the issue is CLI spoofing and, in effect, robocalls.

    While US regulators are busy enforcing STIR/SHAKEN for the common good, there are some loopholes:

    • STIR/SHAKEN presently only works with IP-based telephone networks. Service providers will not be able to properly authenticate calls originating from non-IP systems such as copper landline wires.
    • The authentication process does not indicate whether a call is legal/illegal or wanted/unwanted. It just digitally attests to whether the caller can use the particular number.
    • STIR/SHAKEN applies to only phone calls but not to text messaging. Scammers can still originate illegal messages via spam SMS
    • Finally, the framework is expensive to implement, making smaller carriers shy away from adopting these standards.

    STIR/SHAKEN is indeed the right step forward in reducing robocalls for good, but there is still more work to be done. The issue of crime through robocalling is heavily disguised. Cybercriminals are moving from people to faceless, nameless robots. The i3 Forum report called ‘Caller ID Spoofing’ believes that relying on industry standards alone may not be enough to fight the villain in robocalls. The need of the hour is advanced high-tech real-time capabilities relying on analysis, investigation, probabilities, and a deep dive into patterns of fraud.

    Why regulators and CSPs must work together

    James Bond aficionados already know Agent Q – Bond’s go-to person at the research and development division of the British Secret Service. Q is known for equipping Bond with state-of-the-art tech to fend off villains. Bond is often incredulous about Q’s inventions until they save his life many times in the field. The tempering force, or regulator, in this seemingly tenuous relationship between the technology-savvy Quartermaster and the expert spy, is the Agent M. I find that this trifecta mirrors what we see between regulators, CSPs, and technology. To effectively reduce robocalling fraud, both entities – telcos and regulators – must work together, incorporating the latest technologies.

    And, STIR/SHAKEN is one step in the right direction.

    On their part, US regulators have released a roadmap of anti-robocall principles that serve as a guide for CSPs. They recommend:

    • Enable call blocking and call labeling services to all customers at no charge
    • Implement STIR/SHAKEN call authentication
    • Monitor network traffic, especially high-volume calls, to gauge patterns similar to robocalls
    • Investigate suspicious calls, identify the source, and institute ways to terminate these calls.
    • Confirm the identity of commercial customers to whitelist these
    • Strictly enforce ‘traceback’ so that illegal robocalls can be checked during the transport of voice calls

    Fraud Management Solutions are Telecom’s Agent Q

    Although STIR/SHAKEN is an excellent starting point for the CSPs to address the robocall menace, it is not enough to ensure an end to robocalls. Using analytics in addition to STIR/SHAKEN will provide insights for quick action.

    In fact, in 2019, the FCC allowed telcos to block calls based on reasonable analytics designed to identify unwanted calls without explicit consumer action as long as the consumer is given the option to opt-out of the blocking service. Additionally, in July 2020, the FCC further strengthened analytics-based blocking by adding safe harbors for service providers from liability under the Communications Act and the Commission’s rules for erroneous call blocking. It is now critical to have an advanced analytical solution that provides a multi-tier defense mechanism to combat this. Solutions such as the Subex Fraud Management system makes use of real-time signaling level analysis, paired with advanced machine learning techniques and hybrid rule engine, thus providing new opportunities to drive a prevention-based approach.

    CSPs should urgently take up the issue of robocalling as a priority. Its long-standing impact on customers can be rather severe. Robocall fraud can cause operators to completely lose customer trust and credibility, resulting in substantial revenue loss.

    Time is of the essence. In this respect, reel life mimics real life. As Agent Q famously tells James Bond, “I can do more damage on my laptop, sitting in my pajamas, before my first cup of Earl Grey than you can do a year in the field.”

    Combating Robocalls with Multi-Tiered Detection and Prevention Approach

    Download the point of view

  • War Tactics from ‘The Tomorrow War’ to Combat CLI Spoofing

    War Tactics from ‘The Tomorrow War’ to Combat CLI Spoofing

    Chris Pratt’s ‘The Tomorrow War’ was a blockbuster hit. Gripping, terrifying, and wildly redeeming at the end. No spoilers, but one thing that struck me was the sheer numbers of the alien menace that constituted the movie’s main threat. One single alien monster spawning so many lethal ‘Whitespikes,’ each of which threatens the survival of the human species!

    Dramatic and fantastical: exactly how I like my movies. But it somehow brought to mind a very real current scenario: the ongoing battle against a looming threat in the telecom world – Caller ID(CLI) Spoofing. Sure, it’s plenty fun to watch videos of bystanders receiving calls from friends pretending to be movie stars or even movie stars pretending to be friends (watch Matt Damon’s funny Bourne prank)! But on a larger scale, Caller ID Spoofing is responsible for breeding so many parallel types of fraud, each one equally menacing and capable of creating a lot of damage, threatening the survival of telecom players.

    Scratching the surface of CLI Spoofing

    Caller ID Spoofing is a practice by which voice carriers and aggregators intentionally falsify caller ID information to gain an illicit advantage.It also spawns different types of fraud such as Wangiri (short or faked missed calls generated to leave a notification on the customers’ display prompting them to call back), scam calls (people claiming to be from a trusted company to obtain personal or financial information), and even robocalling (where scammers use an auto-dialer that can broadcast millions of calls within hours).

    There’s more: OBC Spoofing. VM Brute Force. Call Bombing. Bypass Fraud. All of these are offshoots of Caller ID Spoofing. Not such an innocent threat, after all.

    To learn more about the different facets of CLI Spoofing, read this.

    The scale of the problem 

    Unlike sci-fi, though, CLI Spoofing is a big problem. Communication service providers have been struggling with CLI spoofing for ages. In most cases, customers who fall victim to such attacks report extreme dissatisfaction with their telecom providers. Studies show that customers have lost millions of dollars through deceptive callers. Studies show that customers have lost millions of dollars through deceptive callers. In fact, Spoofing accounted for a loss of $2.90 billion, as per CFCA Fraud Loss Survey 2021.

    This is a massive setback for CSPs because of the cost implications. Leading communication service providers report a steady decline of 20% to 30% per year in call pickup rates. Unanswered calls directly impact revenue and margins from national and international voice and messaging communication services. Consumer distrust for the traditional service provider offerings forces them to switch to other alternatives.

    A stitch in time saves nine

    A 2020 report by i3 Forum titled ‘Caller ID Spoofing’ succinctly explains why simply using industry standards is insufficient to fight the CLI menace. The challenge is with reaching critical mass – significant enough to cause a dent in the problem. Similar to how, in the movie, merely dispatching soldiers to fight the ‘Tomorrow Battle’ proved futile until they found a way to get to the root of the problem and tear down the impending attack.

    In the case of CLI Spoofing, the root is Real-time Signaling Risk Intelligence.

    The fact is: nothing beats prevention as the most effective measure of thwarting attacks (watch the movie, you’ll know what I mean). This calls for real-time capabilities based on probabilities, investigation, and comprehensive analysis of fraud signatures.

    Ultimately, a real-time approach using a solution that identifies call signatures, runs ML algorithms, provides threat intelligence, and proactively blocks fraudulent calls; thus, being vigilant and intelligent is the need of the hour.

    This brings me to the story of GO Malta and its pioneering approach to fight CLI Spoofing.

    “We had observed a significant increase in the instances of CLI spoofing and ‘A’ Number manipulation. It had to be handled quickly and effectively because of negative customer impact.”

    Subex Signaling Security

    Customers of GO Malta were troubled by recurring instances of CLI Spoofing that was also creating heavy revenue losses for the operator. Fraudsters were getting increasingly clever, using sophisticated tools to avoid detection and persist with their attacks.

    Subex Subex Signaling Risk Intelligence helped transform the approach from a reactive to proactive one that immediately provided real-time threat intelligence, a prevention-based approach, and faster decision making.

    Within a month, the results were visible.

    Subex helped GO Malta detect spoofed calls before the attack, allowing them to rapidly take action by raising alerts to the respective carriers. They are now securing their revenue, enjoying accurate billing, monitoring channel partners – all thanks to greater fraud detection skills and shorter fraud run-time.

    “The solution helped us reduce spoofed calls, but we also use the tool to determine if an ongoing call campaign is genuine or not.”

     If you’re curious about whether Chris Pratt and his team won the ‘Tomorrow War,’ I promised no spoilers. But, if you want to know how exactly Subex helped GO Malta win its battle against CLI Spoofing, go on and read the case study.

    A proactive approach, that leverages the network to prevent fraud in the digital ecosystem

    Request Demo

  • The Spooky World of Scam Calls

    The Spooky World of Scam Calls

    Scam calls are “unsolicited calls where fraudsters utilize a range of social engineering techniques to steal money or information from the victim through deception (1).” Caller IDs are not spoof-proof, and illegal robocalls are a menace on many communication networks – both of which facilitate scam calls. In 2020, the Federal Trade Commission (FTC) reported receiving 1.25 million fraud complaints.

    Despite technological advances, scam calls are rising by the day as threat actors get increasingly creative at luring their targets. Some act friendly; others threaten victims with dire consequences; some play on fear while others make fake promises. In 2020, Covid-19 topped as the most recent honeytrap for scam callers. As the world grappled with uncertainty around vaccine supply, scammers took advantage to ‘promise’ vaccine delivery in exchange for sensitive personal data (3). In one survey, nearly 3 in 5 adults in the USA reported receiving calls and messages related to the pandemic over the past year (2). In other cases, scam callers appear to offer technical support, monetary prizes, and more.

    The tip of the iceberg

    Scam calls are just the tip of the iceberg. While they may seem more of a menace than harmful, scam calls are often part of a larger plot. Scammers look to collect sensitive personal information from their targets to execute other telecom frauds (4). The results of such fraud for customers can range from identity theft to monetary losses, while for telcos, it involves reputational damage and revenue losses.

    What regulators are doing

    According to Truecaller, more than 59 million people were affected by robocall scams between June 2020 and 2021, losing US $29.8 billion in total (5). Unwanted calls mark the reason behind most of the Federal Communications Commission (FCC) ‘s consumer complaints, and thus FCC has made it their top priority to ensure consumer protection.

    In the USA, the FCC is working on improving network security by clamping down on robocalls in collaboration with telecom companies. Some of their measures include spending dollars on actioning complaints, while others include policy decisions that mandate sharing of customer compliant data and call analytics to better identify robocalls before they reach the targeted subscriber (6). In a bid to mitigate robocalling, the FCC has also issued a set of caller ID authentication standards known as STIR/SHAKEN, whereby voice service providers must verify that the incoming call is actually from the number being displayed on the device screen (5).

    In the UK, there are serious efforts to minimize the instances of robocalling. According to a spokesperson to the BBC, the lower barriers to entry simplify access to telecom infrastructures, making it easy for scammers to disguise themselves as legit businesses and make calls (7).

    5 must-have anti-scam calls capabilities in your fraud management solution

    Operators can take on an active role to thwart scam calls pervading through their network. Here are 5 key capabilities that can help telecom operators reduce the impact of scam calls:

    • Machine learning –Machine learning (ML) allows operators to spot suspicious deviations on calls and SMSs and detect anomalies in real-time with higher accuracy. ML empowers the operators to anticipate, make decisions, and take proactive actions.
    • Signaling security – By monitoring signaling traffic, the fraud management systems can detect attacks in real-time and stop them as they occur, thus securing the network against exploitation.
    • Real-time threat intelligence – Access to real-time threat intelligence, including a dataset of unallocated number ranges, intelligence capture using honeypot networks, gives operators up-to-date knowledge on what’s a threat and what isn’t so they can block scam calls in real-time.
    • Voice and SMS firewalls – Operators should consider extending firewalls to include integration with signaling-based fraud management systems that could identify frauds proactively and update the policies in firewalls to block them in the future.
    • Subscriber/customer awareness – Empowering customers with active knowledge about ongoing trends will help them stay wary of phone scams. It can significantly reduce the number of customers inadvertently becoming victims of scam calls.

    References

    1. https://dev.enki.studio/test/pdf/Point_of_View/multiple-facets-of-cli-spoofing-risks-impact-and-the-way-forward.pdf
    2. https://www.aarp.org/money/scams-fraud/info-2019/phone.html
    3. https://www.rd.com/list/phone-call-scams/
    4. https://dev.enki.studio/test/blog/how-telcos-can-minimize-the-impact-of-scam-calls/
    5. https://www.cnbc.com/2021/09/18/how-fcc-tries-to-fight-robocalls.html
    6. https://www.fcc.gov/consumers/guides/stop-unwanted-robocalls-and-texts
    7. https://www.bbc.com/news/business-59032795

    See how our Fraud Management can help your organization

    Schedule demo

  • Telecom Fraud on the rise: 2021 CFCA Global Telecommunications Fraud Loss Survey

    Telecom Fraud on the rise: 2021 CFCA Global Telecommunications Fraud Loss Survey

    During World War II, Winston Churchill famously quipped, “You never let a good crisis go to waste.” Fast forward to 2020, when the Covid-19 virus caused a global economic shutdown. For a time, the amount of fraud impacting our industry decreased significantly. But, as workers shifted to a “new normal” of working from home and as the global economy has reopened, so has the amount of fraud and abuse impacting our industry.

    In 2021, total global telecom revenues[1] are estimated to be approximately USD 1.8 Trillion. The total amount of telecom revenue loss due to fraud is estimated to be 2.22% of revenues or $39.89 Billion.

    Compared to 2019, fraud losses increased 28% or approximately USD 11.6 Billion. To put that increase into perspective, it is the market value[2] of US companies such as TD Ameritrade Holding, Hartford Financial Services, O’Reilly Automotive, and ADT.

    There are many factors that are contributing to this increase in fraud. The primary reasons are due to:

    •     Increase in cross-industry targeted social engineering schemes (Wangiri, SMS Phishing/Pharming, Social Engineering, Robocalls)
    •     Increase in financial services impersonation frauds using stolen credentials from data breaches
    •     Use of faceless transaction portals to commit Subscription Fraud and Account Take-overs
    •     Increase in the theft of stolen equipment and services
    •     Compromise of network, device, or configuration weaknesses associated with voice-over-IP technologies
    •     Abuse of Voice & Data Service Terms & Conditions

    The increase is also associated with a rise in demand and consumption of telecommunications services. The shift to working from home has fueled insatiable demand for network connectivity and infrastructure. Similarly, the temporary shutdown of entertainment complexes and outdoor entertainment venues due to social distancing requirements has greatly increased the usage of various digital platforms, including social media, gaming, video conferencing, and OTT applications. Mobile voice traffic has also increased, with many prominent communications service providers reporting an enormous escalation in voice traffic since the outbreak of the pandemic. The increase in usage is also driving the increase in the amount of reported fraud loss.

    Fraudsters also use the Covid-19 pandemic crisis to take advantage of unsuspecting victims through targeted social engineering methods such as CLI/ANI Spoofing, Wangiri call-back schemes, SMS Phishing/Pharming, Email Phishing/Pharming and Robocalling. They also harvest personal identifying information to commit subscription fraud and take over victims’ accounts.

    Rahm Emanuel, an American Politician, former Mayor of Chicago, recently echoed Winston Churchill when he said: “You never want a serious crisis to go to waste. And what I mean by that is an opportunity to do things that you think you could not do before.” I agree with this sentiment. As an industry, I believe we can take the recent changes within the telecom industry to better secure and protect our business from fraud and abuse. We have an opportunity to re-frame what good fraud management and security looks like for our industry. By working together, we can make a difference in protecting our customers and our businesses.

    Highlights from the 2021 CFCA Fraud Loss Survey

    Top Fraud Methods Reported in 2021

    Fraud Method Description $USD (Billions)
    Spoofing (IP or CLI/ANI)  Manipulation of the IP address/CLI/ANI to hide someone’s true origination or identity. $2.63
    Wangiri (Call Back Schemes) Call back fraud schemes $2.23
    SMS Phishing/Pharming Theft of personal info or credentials via SMS hacking, phishing, vishing, etc. $2.03
    Subscription Fraud (Application) Creation of false details to gain access to goods and services with no intention to pay $2.03
    IP PBX Hacking Compromised IP PBX used to make fraudulent calls $1.82
    Abuse of network, device or configuration weakness Exploitation of a configuration weakness to gain access to a network or device; Includes VoIP equipment such as a modem or router $1.62
    Account Takeover Manipulation and utilization of existing customer’s account to gain access to a device or service $1.62
    SIM Swapping / SIM Jacking Replacing a new SIM card to gain access to the device or service $1.62
    Phishing / Pharming Theft of personal info or credentials via email hacking, phishing, vishing, etc… $1.62
    Robocalling Use of computerized auto-dialers to deliver pre-recorded messages to perpetrate fraud $1.62

    Top Fraud Types Reported in 2021

    Fraud Type Description $USD (Billions)
    International Revenue Share Fraud (IRSF) Artificial inflation of traffic terminating to international revenue share providers $6.69
    Traffic Pumping (includes: Domestic Revenue Share, Toll Free Traffic Pumping and International Toll Free Traffic Pumping) Abuse of Carrier Interconnect agreements through such things as Traffic Pumping, Switch Access Stimulation, 8yy Dip Pumping and CNAM Revenue pumping schemes $4.54
    Arbitrage Exploitation of the differences in rates between different countries $3.82
    Voice Interconnect Bypass (e.g. SIM box) Unauthorized insertion of traffic onto another carrier’s network. This includes Interconnect Fraud and GSM Gateway Fraud or SIM Boxing $3.11
    Theft / Stolen Goods Equipment theft $3.11
    Domestic Premium Rate Service (In Country) Artificial inflation of traffic terminating to domestic premium service providers $2.39
    Commissions Fraud Schemes used by dealers to collect additional commissions and spiffs $2.15
    Data Charging Bypass Exploitation of network and protocol misconfigurations to bypass charging. For example, interjecting voice traffic onto Viber, Skype or WhatsApp $1.91
    Voice Service Reselling (e.g.: Call Selling) Resale of voice services. $1.91
    Device / Hardware Reselling Resale of equipment such as handsets, tablets, IPTV devices, routers, etc. $1.67

    About the CFCA Fraud Loss Survey

    The CFCA conducts the Fraud Loss Survey to capture a broad view of how much revenue the telecommunications industry is losing, where it is being lost, and what the future holds for fraud losses and fraud management. The full details of the survey results are available to the CFCA membership and related associations that participated in the survey. To learn more, contact the CFCA at fraud@cfca.org.

    References

    [1] Global Telecom Services Market Size Report, 2021-2028 https://www.grandviewresearch.com/industry-analysis/global-telecom-services-market

    [2] Market Values: https://www.economywatch.com/forbes-global-2000-americas-largest-companies

  • Regulators train their sights on SIM Swap. What should telcos do?

    Regulators train their sights on SIM Swap. What should telcos do?

    In April 2018, Gregg Bennett, an entrepreneur in Bellevue, Washington, noticed something odd happening across his email account, after which his phone connectivity immediately zeroed out. Fearing a hacking attempt, Bennett, unfortunately, could do little as the fraudsters took control of his phone number via his SIM, therein gaining access to Bennett’s Amazon, Evernote, Starbucks, and even his Bitcoin account, whereby he lost 100 Bitcoin. 

    Greg Bennett was a victim of SIM swapping.

    SIM swapping is a form of digital identity theft that banks on ‘social engineering.’ Often recognized as the second phase of a fraud attack, SIM swapping happens when fraudsters take control of a victim’s mobile number and from there obtain verification codes like OTPs and URNs that give them unfettered access to protected accounts.

    The trick: How does SIM Swapping work?

    I’ve often likened the finesse of SIM swapping to the sleight of a hand seen at a magic show. One moment the magician directs your attention to the object, perhaps a bird cast in flight. The next second, it vanishes, and as your eyes remain distracted trying to fathom the disappearing act, the real magic trick unfolds in the shadows: The bird pops up into existence somewhere unexpected – a pleasant surprise, a round of applause, a delighted audience.

    But unlike the joy audiences feel at seeing the friendly flutter of feathers again, the ripple effect of SIM swapping is unpleasant and notably sinister.

    Scammers take control of a replacement SIM that is replaced through spurious methods such as reporting a handset lost or stolen, placing requests for SIM replacement, or producing fake documents to get a duplicate SIM. Today, mobile phones are the nerve center of authentication for myriad transactions. So, it doesn’t take more than a few steps thereafter to grant hackers access to personal accounts.

    How SIM swapping works. Source Europol
    How SIM swapping works. Source Europol

    Fun, Funds, and Fame – Motives of SIM Swap Crime 

    Money, certainly, is a driving factor. In the UK alone, SIM swapping cost telecom operators £2.9 million, with over 3,000 cases registered in 2018. In their 2019 IC3 Report, the FBI notes how arresting a leader of a SIM swapping group leader led to the seizure of over US $18 million, five vehicles, a US $900,000 home, and hundreds of thousands of dollars in jewellery. Which.co.uk reported a story about Garth Pollard, a victim of a SIM swapping attack where the attacker spent £13,000 over 48 hours.

    But some hackers engage in SIM swaps simply for the fun of it.

    Take the case of Ruby, whose Instagram handle @ruby was much desired by some of the platform’s users. When Ruby turned out many requests to sell her handle, one hacker decided to scam it off her using a SIM swap. Her provider, AT&T, took note of her complaint and restored her phone number, but it took Ruby much longer to regain her beloved Insta-handle.

    No matter the motive behind the fraud, SIM-jacking is a menace for customers. It also exposes telecom providers to a series of negative effects through lawsuits arising from non-compliance and inadequate consumer protection.

    Seamlessness versus Security – The Telco Dilemma

    It almost makes you wonder why telecoms aren’t doing more to stop this fraud. A chief research officer and expert in the field holds the view that higher security barriers for SIM registrations detract from the ‘seamless experience’ telcos wish to provide their customers. In an effort to make customer acquisition easier, telecoms just might be leaving a window open for SIM swappers to manipulate the system and create trouble for existing customers.

    There is light at the end of the tunnel! Just like how a magician’s repetitive tricks force us to bypass the legerdemain, regulators are now training their sights on SIM swappers.

    The loophole lies in mobile number portability vulnerabilities, which is what the US Federal Communications Commission (FCC) hopes to fix with its new slew of rules. Some of these include introducing a ‘port freeze’ whereby customers can opt to disable SIM duplication requests to avert ‘port out fraud.’ As stated in its recent press release, the FCC proposes that phone carriers be required to securely “authenticate a customer before transferring a phone number to a new device or carrier.”

    African telcos are adopting countermeasures, too. Safaricom, the Kenyan telecom provider, has created an API that alerts banks when a customer’s SIM has been swapped, allowing the bank to decisively protect the customer’s commercial accounts from fraud attacks. African telecoms have also attempted to tighten SIM registration processes in the hope of dissuading scammers. But in emerging markets where standardized national identities are owned by far fewer citizens than there are mobile users, enforcing such dictates (and the efficacy of it) is yet to be known.

    So, how do you begin to protect yourself?

    Creating awareness, protecting privacy, and fostering healthy scepticism among end-users in the online world is a good place to start.

    What does this look like? Think about being cautious when installing apps from non-trusted sources. Refrain from clicking on non-verified links, check before downloading files from unknown senders, and use protocols to keep data private. These are actionable guidelines and advice everyone can follow by default.

    As end-users, here are some tips from Europol (in the infographic) that we can use to minimize the risk of becoming a victim of SIM swaps:

    What can we do to avoid being a victim of SIM Swap? Source: Europol
    What can we do to avoid being a victim of SIM Swap? Source: Europol

    For telecom organizations, a robust defense strategy with multi-layered defense mechanisms, as listed below, can help stay ahead of SIM swap:

    • Features such as link analysis in fraud management systems can analyze, in a visual manner, the different events that are under investigation. This helps anti-fraud analysts understand data patterns from the records and take faster action against fraudsters.
    • AI/ML capabilities support understanding subtle differences in user behavior, thus averting instances of SIM swap fraud before they escalate.
    • Implementing strong process controls such as:

    Subex Fraud Management has built-in capabilities that handle different types of fraud, including SIM Swap, per regional compliance norms.

    Discover more about how Subex Fraud Management helps you sidestep SIM swapping

    Schedule A Demo

  • Combat SIP threats with a Proactive Approach

    Combat SIP threats with a Proactive Approach

    With the transition from telecom operators to digital service providers, the communication processes and the necessary protocols have changed over the years. The digital information is packetized, wherein the transmission happens over IP packets instead of the earlier circuit-switched transmission. Today, VoIP technology has overshadowed traditional communication technologies, which are comprehensible due to the edge it provides in terms of accessibility, portability, scalability, voice quality, flexibility & lower costs.

    While several protocols are used in voice-over-IP (VoIP) communications, Session Initiation Protocol (SIP) has become the most popular. There are various benefits that it brings in for a service provider, which include lower costs, immediate ROI, global potential, mobility & network consolidation.

    With the immense benefits that it brings to businesses, there are also certain risks that are associated with it. Security is one such issue that is of paramount importance to the service providers and their customers, as it pertains to direct and indirect attacks by fraudsters and cybercriminals, leading to financial losses and customer churn for the service providers.

    Did you know Session Initiation Protocol (SIP) which acts as a signaling protocol for VoIP, is the world’s most hacked protocol? 

    Let us look at a couple of instances to put this scenario into context.

    With Covid-19, SIP has become even more widespread due to the enterprise customers placing more SIP endpoints outside the confines of a logical network. An interesting statistic shows the importance of VoIP security-roughly 46% of illegally made calls across the world involve VoIP technology [1]. As much as 65% of the global DDoS attacks in 2018 were aimed at communication services providers [2].

    Also, recently there has been a significant rise in cyber-fraud operations targeting VoIP phone systems worldwide. As per a recent news article, a Gaza-based hacking group was responsible for targeting servers used by more than 1,200 organizations based across over 60 countries, with half of those targets being in the UK. What’s even more worrying is that the hackers worldwide create their own social media groups to share tips and know-how relating to VoIP phone system hacking and organize and coordinate future attacks.

    Although most of the telecom networks are still private, but since they also provide SIP trunks as a service to other smaller carriers or enterprises, they end up exposing some part of their network to a public network and thus become vulnerable to attacks. Interconnect using SIP also exposes telecom networks to attacks as the network laid down for immediate partner and telecom may be private and secure, but if the partner’s network is exposed to a public network, it creates a link to telecom’s network to the public network via other carriers. Also, an international call passes through multiple networks before it’s terminated to the destination. All of the carriers may not have the highest level of security. Hence, such calls are vulnerable to eavesdropping and hi-jacking. SIP is intrinsically vulnerable to a range of attacks, and more importantly, the attackers exploit them to instigate direct or indirect losses to service providers. The below diagram depicts the various threats associated with SIP:

    Combat SIP threats
    Diagram represents the various SIP vulnerabilities

    There are several methodologies of preventing SIP vulnerabilities like network firewalls, cybercriminal simulations, software/hardware patches, etc. But the problem with such arrangements is that fraudsters and cyber criminals still find a way to exploit the inherent loopholes of SIP communication.

    The need of the hour is a proactive approach to detect and nip the vulnerabilities and risks for a service provider in the bud.

    In the traditional approaches, their reactive approach is inadequate and unsatisfactory for the fraud & security strategy of the service providers. This is because of the reliance on xDRs and lack of timely availability of real-time threat intelligence.

    However, we believe the way forward is to have a system in place that uses real-time signaling level analysis, complemented with advanced machine learning techniques and real-time threat intelligence, which will provide new opportunities to drive a prevention-based approach and support operators more effectively to address these types of threats.

    At Subex, we have over 25 years of experience working with telecom operators to proactively mitigate fraud and security risks. To learn more about our approach, reach out to us, and we will bring our expertise in decoding your troubles.

    References:

    1. https://startupanz.com/voip-industry-statistics-2020/

    2. https://www.fiercetelecom.com/telecom/report-two-thirds-ddos-attacks-take-aim-at-communication-service-providers

    Read Our Latest Point of View on SIP Security

    Download Now!

  • Combating Wangiri Fraud: The Need for Collaboration

    Combating Wangiri Fraud: The Need for Collaboration

    What is Wangiri Fraud, and how is it a big problem for CSPs? 

    Wangiri fraud, a call-back scam, is a Japanese word meaning ‘one ring and cut.’ Just as the name suggests, in this form of fraud, fraudsters give a missed call to encourage unsuspecting subscribers to call back to fraudulent premium numbers. CSPs incur both direct and indirect losses due to Wangiri Fraud. It impacts the customers adversely, resulting in customer churn due to high customer dissatisfaction from bill shocks and bad customer experience. It also has a negative impact on the operator’s brand image.

    As per the CFCA 2019 fraud loss survey report, Wangiri is one of the top 5 fraud methods used by fraudsters to carry out fraudulent activities. It is also estimated that telcos are losing close to USD 1.82 billion globally to this fraud. Also, as per the RAG RAFM 2020 Survey, the total global cost for compensation for Wangiri was $1.31 billion.

    The challenges associated with Wangiri Fraud 

    One of the key challenges in detecting Wangiri fraud is the lack of timely availability of threat intelligence. Although telcos frequently update their fraud management systems with the latest hotlist/blacklists, they usually do not have a platform to exchange data in real-time. As a result, telcos always end up being at the receiving end until certain number ranges are tagged as fraud and blacklisted.

    The need for collaboration and community-driven initiatives 

    It is vital to stay one step ahead of the fraudsters in the fraud management space because the fraudsters themselves evolve over time. They change the type of fraud they commit. Therefore, one needs a proactive approach to the problem rather than a reactive one.

    One way to achieve this is to build a collaboration mechanism by which information can flow easily between entities in the telecom ecosystem, making it easier to flag and prevent fraud.

    The industry has looked at ways to share data and have collective databases to identify and share Wangiri fraud numbers. Groups like RAG have actively worked to address some of these problems by bringing industry partners together to innovate and tackle Wangiri fraud effectively.

    The RAG Wangiri Blockchain Consortium is a coming together of telcos and vendors with a common interest in reducing the number of Wangiri fraud calls received by phone users. The consortium does this by using blockchain technology to share intelligence in near to real-time about actual Wangiri calls that have already occurred. This data will help telcos and suppliers improve the algorithms and reference data used for the proactive management of future calls, increasing the likelihood of correctly identifying a Wangiri call before the intended victim suffers harm. The consortium includes more than 100 telcos across Europe, Asia, Africa, and the Americas.

    The Subex-RAG Partnership to leverage RAG Database for fraud detection and prevention 

    Subex, being a pioneer in the Fraud Management space, partnered with the Risk & Assurance Group (RAG) Wangiri Blockchain Consortium to advance innovation in the blockchain space. Subex was one of the first vendors to get into this partnership. This partnership aims to integrate the blockchain database with the Subex Fraud Management system and leverage them as hotlists or reference data to prevent fraud proactively.

    The Benefits 

    Blockchain is a transformative technology, and it is intriguing to see it being used to solve evolving real-world problems such as fraud detection. When it comes to dealing with fraud, the faster the information is exchanged, the better it is to be able to address and prevent fraud. Blockchain enables much faster data exchange. Furthermore, this received data can be actively leveraged for fraud detection in rule-engine and machine learning (ML) techniques. In ML, this can be one of the seed data. Moreover, it can further enhance proactive fraud detection when the data is leveraged from the signaling layer.

    Conclusion 

    Making data intelligence available to the telco community is a crucial aspect of addressing the problem. Strategic partnership and innovations in blockchain mark a new era of sharing data and near-real-time threat intelligence for the telecom industry.

    Learn More on Battling Wangiri Fraud: Need for a Proactive Counter-strategy

    Read this Point of View

  • Mobile Money is Rewriting the Fraud Landscape in Africa

    Mobile Money is Rewriting the Fraud Landscape in Africa

    Users across the globe are rapidly adopting digital wallets to shop, transact, and pay for utilities using mobile money. Easy, convenient, and real-time, these services are proliferating, particularly in markets where banking access is limited. Take Africa, for example, in just a few years, it has raced ahead as the global leader in the mobile payments landscape, with nearly 161 million active accounts and more than 495 billion dollars in transactions.

    In 2020, this mushrooming industry got new impetus.

    Crippled by COVID-19 in what GSMA calls the ‘Great Lockdown of 2020’ in its recent report State of the Industry on Mobile Money 2021, the world was pushed into a recession, limiting the movement of goods and exchange of cash. But in this crisis, mobile money providers seized their inherent advantages to empower economies by providing financial assistance. Here too, Africa leads the way. The GSMA report states that “In 2020, Sub-Saharan Africa continued to account for the majority of growth with 43% of all new accounts.”

    When we think of mobile money in Africa, M-PESA may be the first name that pops to mind – and rightly so. They were the first player to roll out mobile wallets that doubled up as pseudo-bank accounts. Prolific smartphone access has amplified this trend, extending mobile money beyond banking to something people can use for nearly every service, including booking flights, buying insurance, shopping, foreign remittances, and more. A 2020 report titled Mobile Money and Organized Crime in Africa states that “In September 2019, there were 153 active mobile money operators operating in 45 African countries.” Clearly, this market shows no signs of slowing down.

    Origin of risk

    Every new technology comes with a certain risk, and mobile money is no exception. Running these services means establishing multiple and complex back-end integrations with different players, each of which adds to the risk surface. It has drawn the attention of hackers/fraudsters worldwide as they turn their efforts to exploiting pressure points in the mobile money ecosystem.

    What is worrying is that these loopholes aren’t hard to find.

    Weak ID verification systems, poor customer awareness, insufficient security resources, inadequate training, and limited access to best-in-class fraud detection tools are all challenges that make breaches and financial theft possible.

    Regulations are another challenge. Most regulators are struggling to keep pace with how fast the technology is advancing. Striking a balance between user experience and data safety is a constant wrestle. Moreover, as laws take time to catch up, the criminal justice system lags at apprehending offenders. The African Mobile Money report captures this succinctly, stating, “The lack of resources and training of law enforcement concerning the collection and use of technical evidence in the criminal justice system has resulted in difficulties in prosecuting offenders and tackling established organized crime groups.” Further, the low onboarding barriers for mobile money make it a lucrative channel for terrorist financing and money laundering via cross-border payments and international remittances. Without the right checks and balances and cross-country governing rules, mobile money regulatory frameworks tend to be weak, leading to cracks in implementation, particularly pan-country, making it harder to monitor money laundering activities.

    So, what does mobile money fraud look like?  

    Briefly, these include:

    • Customer Acquisition Frauds – Abuse of identity documents to create fake accounts on the platform.
    • Identity Theft – This involves SIM swaps where fake ID proof is used to procure duplicate SIM cards for online transactions, leading to account takeovers.
    • Transaction Frauds:  The mobile money account holder can perform an increasing number of transactions. The number and variety of operations have grown immensely in the recent past. Some of the types of transactions are as follows:
    Representative mobile money transactions
    Figure 1: Representative mobile money transactions
    Source:https://enactafrica.org/research/interpol-reports/mobile-money-and-organised-crime-in-africa

    However, fraudsters can exploit various loopholes in these processes to commit fraud. In transaction frauds, stolen cards, data, or accounts are used to perform unauthorized transactions like income tax refunds, fake social media accounts, phishing, etc.

    • Money Laundering –Money laundering is the illegal process of making large amounts of money generated by criminal activity, such as drug trafficking or terrorist funding, appear to have come from a legitimate source. Money launderers can exploit mobile money services to transfer the proceeds of crime to co-conspirators located in other countries, or supporters of terrorist organizations can exploit.
    • Internal Frauds – Frauds conducted internally by merchants or employees with access to customer information.

    Uganda’s mobile money network took a significant hit on October 3, 2020, when one of the companies providing services to telecom companies was exploited by fraudsters, leading to 3.2 million stolen dollars. The theft was executed through unsuspecting telecom companies, and money was exchanged through mobile money payment systems using 2000 SIM cards. Many reasons are implicated in the execution of this fraud, including malicious telecom agents, fake KYC, and spurious campaigns.

    Clearly, the challenges of verification and identification are the weakest links. Without being able to clarify whether transactions are authentic, issues like money laundering for terrorist financing emerge. As stated in the Mobile Money and Organized Crime in Africa report, the sheer diversity of national ID documents as well as low national ID coverage in Africa further compound this challenge.

    Need for a Multi-Pronged Strategy 

    With mobile money adoption rates increasing in Africa bearing the promise of even more growth, mobile operators and digital wallet companies need a proactive mindset to stay ahead of fraud. Well-defined training programs, for instance, can educate customers and internal teams on the different types of fraud risk and vectors. Implementing the right fraud management tool, which has the capability to monitor suspicious activity related to internal employees, partners, agents, sanctioned lists, etc., and outfitted with robust AI/ML capabilities that track millions of daily transactions and detect abnormal behavior is extremely important. Further, when coupled with Anti-Money Laundering (AML) capabilities like risk categorization, suspicious activity monitoring, and AML watchlists, such solutions provide a robust defense, helping operators ensure themselves from the evils of mobile money fraud.

    Subex enabled a Tier-1 African Operator to uncover Mobile Money Fraud and help them save USD 3 million

    Download Case Study

    Sukshitha Rao is a Product Marketing Specialist responsible for Fraud management portfolio at Subex. She is a postgraduate in management from Symbiosis Institute of Digital and Telecom Management with Marketing as her major. She has about two years of work experience in the IT industry.

  • Customer Protection – More Critical Than Ever

    Customer Protection – More Critical Than Ever

    In August 1992, I bought my first house. The property already had an existing landline, and for convenience, we took the line over and retained the same number. The number associated with the line ended ‘2222’, which at the time we thought was pretty cool until we started receiving calls at 3:00 AM from people trying to order taxis! This was my first real experience of ‘nuisance calls.’ Still, as annoying as getting woken up occasionally by a drunk man or woman ringing the wrong number in the early hours of the morning, at least their intent was quite innocent – they just wanted to get home.

    Through the years, I experienced the ‘waves’ of unsolicited sales and marketing calls from telemarketing companies, which somewhat took the focus off the now occasional ‘taxi call.’ Industry and regulator schemes do try to keep your number private and/or opt-out from these types of calls helped initially, but the perpetrators have modified and evolved their approach, so these types of calls persist.

    30 years on the ‘Telesales’ related calls have now been eclipsed by something far more sinister – ‘the scam call.’ This is not a new phenomenon, and many in the UK will recall the first time they got a call from the ‘Windows Support team’! However, for UK and Europe, these types of calls have been relatively low historically, but they are increasing rapidly, and there are strong parallels with the USA experience.

    In the USA, the term ‘robocalling’ was created to cover the different types of unsolicited, largely automated calls impacting end customers. The issue reached such a level that in 2017 the FCC brought in rules allowing phone companies to block unwanted ‘robocalls’ and encouraged carriers to offer customers more advanced call screening options and solutions. However, in 2018 analysis suggested there were still 4 billion ‘robocalls’ being received per month, with the largest percentage of these calls being ‘scam calls.’ Due to the continued customer complaints and negative publicity generated from the victims of these scams, the FCC brought in further regulations/recommendations that provided carriers with the approval to ‘aggressively’ address ‘robocalling.’ We saw the start of the rollout of initiatives such as STIR/SHAKEN to identify the use of CLI Spoofing – to facilitate the scam. Even with these initiatives, the problem persists.

    In Europe, industry groups & regulators have been looking at this issue for some time, but although discussions continue, in most countries, a solution is some way off.

    If I look at my own experience of ‘scam calls’ up until recently as well as my personal landline, I also had a separate business line in the same property. The lines are provided by different UK operators, but over the last couple of years, they have both demonstrated the same behaviors, namely:

    • Reduction in genuine calls to almost zero. I recently got rid of my business line as it had largely been made redundant by a combination of ‘Teams/Skype/Mobile service.
    • A massive increase in ‘Scam calls’ across both lines.

    Although this article references my experience with my fixed-line services, Mobile phone users are equally vulnerable. SMS provides another channel for organized criminals to scam users through various techniques, e.g., Smishing.

    Given that a ‘silver bullet’ solution is not likely to be available in the near future, it is imperative for European operators to act decisively and proactively to ensure they rapidly implement appropriate solutions and controls to protect their customers. If they do not, they take the significant risk of losing ground to competitors who are seeing enhanced consumer protection as an essential service differentiator, handling increased levels of complaints and customer churn, and having to also deal with the associated negative publicity. There is also an inevitability that as the impact of scam calls increases, we will see increased regulatory pressure/intervention on operators to act anyway, so addressing the issue proactively is the sensible approach.

    At Subex, we have over 25 years of experience working with telecoms operators to proactively mitigate fraud and security risks. Our team has created the Consumer Protection Service to support operators in proactively identifying scam calls and other types of unsolicited behaviors by leveraging protocol analysis and AI/ML techniques on traffic.

    Find out more about our service and to see how we can help you deliver enhanced protection to your customers.

    Schedule Demo

  • The True Cost of Insurance Fraud

    The True Cost of Insurance Fraud

    “Identity theft.” “Consumer fraud.” “Insider trading.” “Falsifying data.” 

    Many of us may instantly know what each of these words mean thanks, in part, to the rising numbers and types of fraud that plague customers and corporations, making headlines globally. Over the past two years, fraud has become a growing menace, with an average of 6 frauds being reported per company.

    Nearly every industry incurs some amount of financial loss from external threats or malicious insiders who intentionally defraud organizations through process loopholes. But the insurance industry is particularly susceptible due to a wide canvas that includes many channels, products, and processes for fraudsters to manipulate. Insurers report different types of fraud, including internal fraud, external fraud, underwriting fraud, and claims fraud, each having varying degrees of deceit and preparation. Fraudsters are also constantly evolving their techniques, becoming more and more sophisticated with convincing threat actors that exploit system ambiguities, especially in newer digital channels and networks. More recently, banking, financial services, and insurance (BFSI) companies are seeing a spike in what is being termed as ‘cross-channel’ fraud, whereby hackers steal user credentials from one channel to execute fraud on another channel. But setting aside the higher risk posed by digitalization, even in-person and traditional fraud techniques are advancing and remain a serious threat.

    Drivers of insurance fraud

    As in any other industry, the drivers for insurance fraud boil down to three aspects – pressure, opportunity, and rationalization. People who are overwhelmed by financial pressure may deliberately look for easier ways to make money. Some may find opportunities to derive financial gain through weak links that can be exploited. Others may rationalize padding a claim or exaggerating an incident with the view that they have paid their premiums diligently and yet have never claimed anything to date.

    Insurance scams are executed by individuals or corporations engaging in ‘opportunistic’ or ‘professional’ fraud. Opportunistic fraud is more common, and perhaps a part of human nature often found at the nook where opportunity and rationalization meet. Examples here are inflating a medical bill or falsifying the value of stolen/damaged goods. Professional fraud involves a group of individuals that defraud insurers through schemes like arson-for-profit where owners deliberately set fire to their property to claim their policy or staged auto accidents that entrap unsuspecting motorists into collisions.

    While many consider insurance fraud as a ‘victimless crime’ affecting only insurance giants that can easily stomach the losses, its true impact is far larger than imagined.

    The actual losers of fraud

    • Fraud losses cost insurers steeply.A study of global claims fraud showed that 3-4% of all claims filed are fraudulent. The Coalition Against Insurance Fraud puts the global cost of insurance fraud at USD 80 billion. It is important to note that these losses do not include corporate spending on anti-fraud controls, compliance, and employee training. What is often unknown is that when insurers pay out large sums in fake claims, it weakens their financial position, causing grave consequences to other stakeholders.
    • Policyholders suffer escalating premiums.Theoretically and socially, insurance is a boon. It protects society’s wealth from risk and maintains cash flow despite adverse events. For example, in light of COVID-19, some American auto insurers have actually issued rebates of 15-25% on premium payments of policyholders. However, escalating fraud losses compromise an insurer’s ability to refund gains to stakeholders. To make matters worse, underwriters often increase the price of the insurance products and plans to combat these losses, forcing honest policyholders to bear higher or excess premiums for a reasonable risk. In effect, everybody loses.
    • Fake pay-outs drive organized crime globally.Ill-gained proceeds from insurance fraud can fuel terrorism and organized crime across the world. It also acts as a prime channel for money laundering. In one such case, prosecutors in the state of New York uncovered a massive auto-insurance fraud that cost insurers  millions of dollars. The perpetrators included an outfit of Russian gangsters, doctors, and lawyers that set up fake accident scenes and clinics. Soon after the incident, the New York Senate passed three bills to crackdown on auto-fraud through tougher measures.

    One of the biggest obstacles to combating insurance fraud is the fact that most countries across the globe do not consider insurance fraud as a crime. This means that reporting insurance fraud to a policeman is usually ineffective because law enforcement agencies lack the protocols to investigate insurance fraud. It is no wonder then that the global insurance fraud detection market has been seeing steady growth, accounting for nearly USD 4.1 billion in 2018.

    Faced with the rising frequency and sophistication of fraud coupled with a lagging regulatory pace, it is up to insurers to identify modern, faster, and more effective ways to shield themselves and their stakeholders from fraud.

    Learn more on Insurance Fraud: Building a multi-faceted defense in a risky digital world

    Download the Point of View