AI use case

AI for telecom fraud detection (SIM swap, IRSF and Wangiri)

AI that protects the operator's own network, revenue and numbers from fraud: it watches call, messaging, roaming and account activity to detect SIM swap and port out takeovers, international revenue share fraud (IRSF) and Wangiri one ring scams, blocks or flags them in real time, and shares risk signals with banks and other businesses that rely on the phone number for security. Scam calls aimed at subscribers are handled by call blocking.

By Len Debets · Last verified 27 September 2026 · 4 public deployments

30%
Reported detection improvement
Vodafone, organization claim.
USD 750,000 to USD 6 million
Indicative value per year
A mobile operator with 10 million subscribers. Worked example, see how it is calculated.

What problem does it solve?

Telecom fraud hits operators and their customers at once. In a SIM swap or port out attack, a criminal takes over a victim's phone number and with it the one time passcodes that protect bank accounts and crypto wallets. In international revenue share fraud, criminals push calls to premium numbers they control, often held in another country, through compromised SIM accounts or hacked company phone systems (PBXs), and take a share of what the victim is billed. In Wangiri scams, a call rings once so the victim calls back to an expensive premium number.

These patterns move fast and change constantly. Rules written for last month's attack miss this month's, and blocking too aggressively cuts off genuine calls and customers. Telstra points out that fraudsters who get enough personal information can persuade customers to give up their one time codes and then access bank and superannuation accounts and investment or crypto wallets. The operator holds the signals that reveal these attacks, such as a recent SIM change, an unusual calling pattern or a number that behaves like a fraud line, but they are only useful if they are scored in real time and shared safely.

How does it work?

  1. Stream the signals. Call detail records, signalling, SIM and port events, roaming records, account changes and customer reports flow into a real time scoring layer.
  2. Score behaviour, not just lists. Models learn normal calling and account behaviour and flag deviations: a burst of short international calls to a high cost range, a new SIM followed by logins elsewhere, a number whose call pattern matches known Wangiri campaigns.
  3. Act by risk. High confidence fraud traffic is blocked at the network; account takeovers trigger step up checks; uncertain cases go to fraud analysts with the evidence.
  4. Share risk signals. Through standard network APIs, such as SIM Swap and Number Verify, banks and online services can ask whether a number was recently swapped or behaves unusually, and use the answer in their own risk decisions.
  5. Learn from outcomes. Analyst decisions, customer reports and chargebacks feed back into the models, so detection keeps up as fraudsters change tactics.
Audience
Back office
Autonomy
Supervised agent
Adoption
Early adopters
Channels
API and system to system, Phone and voice, SMS

What is it worth?

Benchmarks are computed from the public deployments below: one data point per organization per KPI, with who made each claim.

Value benchmarks for AI for telecom fraud detection (SIM swap, IRSF and Wangiri)
KPIMedianReported rangeData pointsClaimed by
Detection improvementToo few to pool
30%
11 organization

Value drivers: Risk and loss reduction, Customer experience, Lower cost to serve, Revenue growth.

Indicative value

A mobile operator with 10 million subscribers

USD 750,000 to USD 6 million

Operator fraud losses avoided per year

How this is calculated

Formula: subscribers * fraudCostPerSubscriber * reduction. The low scenario uses every low input, the high scenario every high input.

InputLowHighBasis
Mobile subscribers subscribers, subscribers10,000,00010,000,000The reference operator.
Fraud losses and write offs per subscriber per year (IRSF, subscription and SIM related fraud) fraudCostPerSubscriber, USD per subscriber per year0.52Editorial assumption. Replace with your own fraud loss reporting.
Share of fraud losses prevented by AI detection reduction, fraction of fraud losses0.150.3Editorial assumption, replace with your own. No source on this page measures prevented operator fraud losses; the only measured result is Vodafone's 30% improvement in bank scam detection in a UK pilot, which concerns authorised push payment scams rather than IRSF, Wangiri or subscription fraud.

What it leaves out: Operator losses only. It leaves out losses avoided by customers and banks, revenue from selling fraud signals through network APIs, analyst time saved, and the cost of false blocks.

Who already uses it?

4 public deployments, strongest evidence first. Grades: A regulator or audit, B the organization itself, C vendor case study, D anonymous or estimate.

Telstra

Australia · Telecommunications · 2025

ProductionGrade B

Quantium Telstra built two services in collaboration with Commonwealth Bank. Scam Indicator detects and intercepts suspected scam calls to bank customers in real time and was later extended to landlines. Fraud Indicator, live from early 2025, securely shares intelligence about unusual mobile service usage so the bank can spot fraudsters opening accounts with a phone number they control. Telstra describes the Scam and Fraud Indicator as using AI and says it has safeguarded thousands of customers and prevented millions of dollars in fraud since 2023; the expected gain in detection of fraudulent accounts was published as a forecast.

No outcome disclosed.

Vodafone

United Kingdom · Telecommunications · 2024

ProductionGrade B

Vodafone Carrier Services launched Scam Signal, an API that analyses real time network data during a live bank transaction to detect social engineering behind authorised push payment fraud, so banks can stop fraudulent transfers as they happen. It sits in Vodafone's Identity Hub next to the SIM Swap and Number Verify APIs, which use CAMARA open standards. JT Group, working with FICO, was the first channel partner to offer it. In a three month pilot with a UK bank that Vodafone does not name, scam detection improved by 30%.

  • Detection improvement: 30%, three month pilot with a UK bank
    "Scam detection using this service improved by 30% after only three months of a successful pilot with a leading UK bank."
    Claimed by: organization

Telstra

Australia · Telecommunications · 2022

AnnouncedGrade B

In January 2022 Telstra said it had started working with organisations in the banking industry and would provide a risk rating, a number on a risk scale, when a banking organisation asks whether a mobile service used as a form of identity has had a recent SIM swap or port out. Banks and credit unions would request it when a customer makes a transfer, especially to a new recipient, and use it to ask for more information rather than to block the customer automatically. Telstra said it was considering applying the technology in retail, insurance, transport and logistics, social networking and online gaming. No results are published, and no later Telstra source cited here confirms how widely the rating is used today.

No outcome disclosed.

Telstra

Australia · Telecommunications · 2021

ScaledGrade B

As part of its Cleaner Pipes initiative, Telstra blocks suspected scam calls in its network before they reach customers. Upgrades in 2021 made blocking more aggressive, improved detection of Wangiri one ring calls from international premium numbers and of spoofed calls that pretend to come from local numbers or trusted brands, and doubled the monthly volume blocked within four months. Telstra says it keeps evolving its algorithms and detection methods and takes care not to block genuine calls. From December 2024 it added Telstra Scam Protect, an in house network feature that warns customers on screen about calls that look spoofed, arrive from overseas while showing a local number, or come from a number with a suspicious calling pattern. Its Scam Protect article (published March 2025, updated May 2026) reports blocking more than 11 million scam calls a month on average and Scam Protect warnings on an average of 12 million calls a month.

No outcome disclosed.

How do you implement it?

A model agnostic playbook: what to prepare, the order to build in, and what goes wrong.

Data you need

  • Call detail records and signalling data in near real time
  • SIM change, port out and account change events with timestamps
  • Labelled fraud cases from the fraud team and customer reports
  • Number ranges and destinations known for high cost or fraud use

Systems to integrate

  • Network switching and signalling platforms for blocking
  • Fraud management system and case tools
  • Customer account and SIM management systems
  • Network API gateway for SIM Swap, Number Verify and similar services
  • Customer reporting channels such as short codes for spam and scam reports

Complexity: High

Real time scoring on network events at operator scale is demanding, fraud patterns shift quickly, and sharing signals with banks brings privacy, consent and contractual work.

  1. 1

    Map the fraud types and their cost

    Quantify losses per fraud type (IRSF, Wangiri, subscription fraud, SIM swap) and decide which ones justify real time detection first.

  2. 2

    Get the events in real time

    Attacks on hacked phone systems are often run outside office hours so they last longer, and a daily batch finds them after the bill has grown. Stream call records and SIM events instead.

  3. 3

    Combine rules and models

    Keep proven rules for known patterns and add models that catch unusual behaviour, with every model alert reviewed by analysts until precision is proven.

  4. 4

    Tune the blocking threshold on genuine traffic

    Measure how many genuine calls and customers each threshold would block before switching it on, and give customers a quick way to report wrong blocks.

  5. 5

    Offer signals to partners carefully

    Expose SIM swap and verification signals through standard APIs with contracts, consent and purpose limits, starting with banks.

Guardrails

  • Blocking only above a validated confidence threshold, with a fast route to unblock genuine customers
  • Signals shared with partners limited to risk indicators, never raw call or location records
  • Consent and purpose limitation for every partner use of network data
  • Analyst review of account level actions such as suspending a SIM

KPIs to instrument

  • Fraud losses per fraud type, normalised for traffic
  • Detection rate and time to detect for confirmed fraud cases
  • False positive rate, including genuine calls blocked and customers wrongly flagged
  • Partner outcomes from shared signals, such as scams stopped by banks

Human in the loop

Fraud analysts review model alerts that lead to account actions, set blocking thresholds and approve new rules. Customer service can reverse a block after identity checks, and every reversal is fed back to the models.

Common failure modes

Blocking genuine customers
An aggressive threshold cuts off legitimate international callers or new SIM users. Measure impact on genuine traffic before and after.
Fraudsters adapt faster than rules
Static rules catch last month's pattern only. Retrain often and watch for sudden drops in alerts.
Signals without context
A bank treats a recent SIM swap as proof of fraud and locks out a customer who just replaced a phone. Share signals as risk inputs, not verdicts.
Privacy overreach
Partners ask for more network data than they need. Limit sharing to purpose bound risk indicators.

What are the risks and rules?

EU AI Act

Depends on design

Fraud detection is not listed as high risk in Annex III, and point 5(b) explicitly excludes systems used to detect financial fraud from the creditworthiness category. Blocking fraud traffic is not normally a safety component of critical digital infrastructure (point 2). The tier can change if the same scores are reused for an Annex III purpose: eligibility for essential public assistance benefits and services (point 5(a)), creditworthiness or credit scoring of natural persons (point 5(b)), or risk assessment and pricing for life and health insurance (point 5(c)). A voice or chat agent that takes fraud reports from customers also carries the Article 50(1) duty to tell people they are dealing with an AI system.

Guidance

  • Cyber Telecom Crime Report 2019 (Europol European Cybercrime Centre and Trend Micro Research, Europe). Threat models for telecom fraud, including international revenue share fraud through hacked PBXs and SIM accounts, and Wangiri callback fraud to premium numbers.
  • CAMARA SIM Swap API (CAMARA project (Linux Foundation), Global). Open API standard that lets banks and online services check whether a SIM was recently changed, used by operators including Vodafone.
  • APP scams (Payment Systems Regulator, Europe). UK reimbursement rules for authorised push payment scams, split between sending and receiving firms; Vodafone cites this reimbursement duty as a reason banks are turning to network based APIs.

Controls to put in place

  • Data protection impact assessment for fraud scoring and signal sharing
  • Documented thresholds and rules with change control
  • Monitoring of false positives and customer complaints about blocking
  • Contracts and technical limits on partner use of network risk signals

Frequently asked questions

How do operators help banks stop SIM swap fraud?
By sharing a risk signal rather than data. In 2022 Telstra said it would give banks, on request, a rating on a risk scale that shows whether a mobile service used for identity has had a recent SIM swap or port out, so the bank can ask for more information before a transfer goes ahead.
Does network data really improve fraud detection?
Vodafone reports that scam detection improved by 30% after three months of piloting its Scam Signal service with a UK bank; that service targets authorised push payment scams, and Vodafone does not say whether it uses AI. Telstra says the Scam and Fraud Indicator, built by Quantium Telstra with CommBank, uses AI; Fraud Indicator shares intelligence about unusual mobile usage to help detect fraudulently opened accounts, and the gain of more than 25 per cent announced at launch in 2025 was an expectation, not a measured result.
What is Wangiri fraud and can it be blocked?
Wangiri calls ring once from an international number so the victim calls back to a costly premium number. Operators block known patterns in the network; Telstra described improving its Wangiri blocking in 2021, when its platform blocked around 13 million suspected scam calls a month.

How to cite this page

Blits.ai AI Use Case Library, "AI for telecom fraud detection (SIM swap, IRSF and Wangiri)", last verified 27 September 2026, https://www.blits.ai/ai-use-cases/telecom-fraud-detection. Licensed under CC BY 4.0. Method: how we verify use cases.

Changelog
  • 27 September 2026: First published

Related use cases

Telecommunications

AI spam and scam call blocking for mobile and landline subscribers

AI in the operator's network that protects subscribers from unwanted calls: it analyses incoming calls in real time, blocks known fraudulent calls, and labels suspected scam, spam and spoofed calls on the customer's screen before they answer, so subscribers can decide whether to pick up. Fraud against the operator itself, such as SIM swap or revenue share fraud, is a separate use case.

Deployments
5 public, best grade B
Autonomy
Autonomous
BankingPayments and cards

AI scam intervention for instant payments

AI that talks to the customer when they are about to authorise an instant payment that looks like a scam: it combines the payee check and the risk score, asks targeted questions about the payment in plain language, explains the specific scam pattern, and holds, delays or escalates the payment to a human specialist when the risk stays high. Unlike fraud scoring, which stops payments the customer did not make, it protects customers from payments they are being manipulated into making.

Deployments
6 public, best grade B
Reported detection improvement
300%
Starling Bank, vendor claim
BankingPayments and cards

AI for application and identity fraud detection

AI that checks incoming account and loan applications for forged or AI generated documents, synthetic and stolen identities, and coordinated application rings, by analysing documents, device and application data across the whole queue and cross checking against bureau and official sources.

Deployments
6 public, best grade B
Reported detection improvement
2.5x
Department for Work and Pensions, organization claim
Telecommunications

AI assistant for telecom order to activation and eSIM onboarding

An AI assistant that takes a new or existing customer from order to a working service: it collects and checks the order details, guides number porting, eSIM download or SIM activation and installation appointments, tracks the order and fixes or escalates the step that is stuck, on messaging, app, web or phone.

Deployments
3 public, best grade B
Reported automation rate
76%
Singtel, organization claim
BankingPayments and cards

AI for money mule account and network detection

Graph and behavioural machine learning that finds money mule accounts and the networks around them, such as circular flows, layering chains and clusters of newly linked accounts, and supports investigators in tracing scam proceeds and restricting accounts before the money is gone.

Deployments
3 public, best grade B
Autonomy
Copilot