For most of the past two decades, telecom fraud was a margin problem. International revenue share fraud (IRSF), Wangiri callbacks, SIM-box bypass and subscription fraud cost operators money, and fraud teams were judged on how much they recovered. That framing no longer holds. Operators now sit at the centre of a consumer scam economy in which their networks are the delivery channel, their SIMs the authentication factor and their data the early-warning signal, and regulators are starting to write that role into law.
The size of the problem
The Communications Fraud Control Association’s 2025 survey puts global telecom fraud losses at $41.82 billion, up from $38.95 billion in 20231. The schemes causing the largest losses were, in order, subscription fraud, first-party subscription fraud, targeted social-engineering scams, account takeover, and mass phishing and smishing1. Wholesale carriers report a similar picture: in the Global Leaders’ Forum 2025 survey, 67% of carriers reported high volumes of IRSF and 69% classified fraudulent traffic as a top priority, the highest level the survey has recorded2.
Carriers have made fraud a strategic priority
Share of wholesale carriers, %, Global Leaders’ Forum fraud survey, 2025 (%)
Source: Capacity, “2025 GLF Fraud Report sounds alarm: Collaborate or face collapse” (2025)
Consumer harm is larger still. The Global Anti-Scam Alliance’s 2025 survey found that 57% of adults worldwide had experienced a scam in the previous year and 23% had lost money3. In the UK, payment-fraud losses reached £1.28 billion in 2025, up 4%, with authorised push payment (APP) losses up 19% to £576.4 million4. Only 17% of APP cases began on telecoms networks, but those cases accounted for 28% of losses, because phone-based impersonation tends to involve larger sums4.
Telecom-originated scams are fewer but costlier
Share of UK APP fraud that began on telecoms networks, %, 2025 (%)
Note: Most APP cases (66%) began online.
Source: UK Finance, “Fraud remains a national security threat as criminals steal almost £1.3 billion” (2026)
The attack surface is the identity layer
SIM-swap fraud shows how telecom identity has become financial identity. The UK fraud-prevention service Cifas reports that SIM-swap attacks grew by 38% last year, driven by reliance on SMS one-time passcodes and increasingly executed online rather than in store6. The same mechanics, number porting, eSIM activation and passcode interception, underpin account takeover at banks, wallets and marketplaces. Operators are responding with automation: every CFCA respondent uses a fraud management system with some automation, 97% have dedicated fraud teams, and three-quarters now use machine learning or AI, roughly double the 2023 level, although 53% describe their AI experience as ‘beginner’1.
AI is raising the stakes on both sides. The same CFCA-based analysis cites a 2026 industry survey in which 87% of security professionals said AI is significantly increasing the volume of attacks they face and 39% named deepfake voice fraud as the AI-enabled threat posing the greatest risk1. Voice cloning makes impersonation calls more convincing, which is precisely the channel that already drives the highest-value losses.
Liability is shifting accordingly. UK banks reimbursed £354.3 million of APP losses in 2025, equivalent to 61% of the total, and the banking industry is now calling for firms in the technology and telecoms sectors to contribute financially, as well as sharing intelligence and capabilities, to support fraud prevention4. Whether or not that argument prevails, operators should expect to be asked to show what they did to stop a scam that ran over their network.
Regulation: from charters to duties
The most significant change in 2026 is regulatory. The direction is consistent across markets: operators must know their customers and their traffic, block what they can and share what they know. The status below is as of late September 2026.
- United Kingdom. In July, Ofcom finalised rules requiring mobile providers to block numbers and messages used by scammers, set volume limits on pay-as-you-go SIMs, run know-your-customer and know-your-traffic checks on business message senders and corroborate alphanumeric sender IDs; it also told operators to withhold caller ID on calls that appear to come from UK mobiles roaming abroad unless they can be verified5. Operators already block an estimated 600 million-plus scam messages a year5. In September, industry guidance developed with the Home Office, Ofcom and the Information Commissioner’s Office clarified when providers may lawfully share fraud data with other operators, law enforcement and banks7.
- Australia. Treasury released draft Scams Prevention Framework codes in May 2026, including a sector code for telcos that requires identity verification before services are supplied. Obligations backed by civil penalties are set to commence by at least 31 March 2027, and a proposed dispute-resolution model would split liability equally between entities in breach8.
- European Union. The Payment Services Regulation, provisionally agreed in late 2025, treats bank-impersonation fraud as unauthorised for reimbursement purposes and introduces a duty for electronic communications providers to cooperate with payment providers on fraud prevention; publication in the Official Journal was expected around mid-20269.
- United States. In April 2026 the FCC proposed tighter know-your-customer obligations for originating voice providers, with penalties potentially assessed per illegal call11.
Operator–bank data sharing is where the value is
Operators cannot see inside encrypted messaging apps or read call content, but they can see the signals that precede a scam: unusual calling patterns, high-volume messaging, suspicious infrastructure, abnormal roaming and recent SIM changes12. Shared in real time with banks, those signals change outcomes. The Scam Signal service, which combines network intelligence with bank transaction data through APIs, went live in South Africa in October 2025 as its second market after the UK; UK deployments have delivered detection improvements of up to 40% with a false-positive ratio of 3:1 for certain strategies10.
An operating agenda for 2027
Three priorities follow. First, close the identity gaps: SIM swap, eSIM activation and porting should carry the same step-up controls a bank applies to a new payee. Second, build the evidence trail regulators will ask for, including blocking volumes, response times and customer-verification outcomes, from the same data used to detect fraud. Third, turn network signals into services for banks, priced on avoided loss, with privacy by design so that sharing stays lawful.