Executive briefingTelecom industry trends

Telecom fraud and scams in 2026: from revenue leakage to duty of care

Fraud losses on operator networks are still rising, but the bigger shift is regulatory. Operators are being asked to block, verify and share on behalf of the whole payments ecosystem, and to prove that they did.

7 min read By · Executive briefing
$41.8bn
global telecom fraud losses in 2025, up from $38.95bn in 2023 (CFCA survey)1

Key takeaways

  • The CFCA puts global telecom fraud losses at $41.82 billion in 2025, up from $38.95 billion in 20231.
  • Scams are a whole-ecosystem problem: 17% of UK authorised push payment fraud cases start on telecoms networks, but they account for 28% of losses4.
  • Regulators are moving from voluntary charters to enforceable duties: Ofcom’s July 2026 messaging rules, Australia’s Scams Prevention Framework codes due by March 2027 and an EU cooperation duty for electronic communications providers589.
  • Operator–bank signal sharing works: network-intelligence scam detection has improved detection rates by up to 40% in UK deployments10.

For most of the past two decades, telecom fraud was a margin problem. International revenue share fraud (IRSF), Wangiri callbacks, SIM-box bypass and subscription fraud cost operators money, and fraud teams were judged on how much they recovered. That framing no longer holds. Operators now sit at the centre of a consumer scam economy in which their networks are the delivery channel, their SIMs the authentication factor and their data the early-warning signal, and regulators are starting to write that role into law.

The size of the problem

The Communications Fraud Control Association’s 2025 survey puts global telecom fraud losses at $41.82 billion, up from $38.95 billion in 20231. The schemes causing the largest losses were, in order, subscription fraud, first-party subscription fraud, targeted social-engineering scams, account takeover, and mass phishing and smishing1. Wholesale carriers report a similar picture: in the Global Leaders’ Forum 2025 survey, 67% of carriers reported high volumes of IRSF and 69% classified fraudulent traffic as a top priority, the highest level the survey has recorded2.

Exhibit 1

Carriers have made fraud a strategic priority

Share of wholesale carriers, %, Global Leaders’ Forum fraud survey, 2025 (%)

Source: Capacity, “2025 GLF Fraud Report sounds alarm: Collaborate or face collapse” (2025)

Consumer harm is larger still. The Global Anti-Scam Alliance’s 2025 survey found that 57% of adults worldwide had experienced a scam in the previous year and 23% had lost money3. In the UK, payment-fraud losses reached £1.28 billion in 2025, up 4%, with authorised push payment (APP) losses up 19% to £576.4 million4. Only 17% of APP cases began on telecoms networks, but those cases accounted for 28% of losses, because phone-based impersonation tends to involve larger sums4.

Exhibit 2

Telecom-originated scams are fewer but costlier

Share of UK APP fraud that began on telecoms networks, %, 2025 (%)

Note: Most APP cases (66%) began online.

Source: UK Finance, “Fraud remains a national security threat as criminals steal almost £1.3 billion” (2026)

The attack surface is the identity layer

SIM-swap fraud shows how telecom identity has become financial identity. The UK fraud-prevention service Cifas reports that SIM-swap attacks grew by 38% last year, driven by reliance on SMS one-time passcodes and increasingly executed online rather than in store6. The same mechanics, number porting, eSIM activation and passcode interception, underpin account takeover at banks, wallets and marketplaces. Operators are responding with automation: every CFCA respondent uses a fraud management system with some automation, 97% have dedicated fraud teams, and three-quarters now use machine learning or AI, roughly double the 2023 level, although 53% describe their AI experience as ‘beginner’1.

AI is raising the stakes on both sides. The same CFCA-based analysis cites a 2026 industry survey in which 87% of security professionals said AI is significantly increasing the volume of attacks they face and 39% named deepfake voice fraud as the AI-enabled threat posing the greatest risk1. Voice cloning makes impersonation calls more convincing, which is precisely the channel that already drives the highest-value losses.

Liability is shifting accordingly. UK banks reimbursed £354.3 million of APP losses in 2025, equivalent to 61% of the total, and the banking industry is now calling for firms in the technology and telecoms sectors to contribute financially, as well as sharing intelligence and capabilities, to support fraud prevention4. Whether or not that argument prevails, operators should expect to be asked to show what they did to stop a scam that ran over their network.

Regulation: from charters to duties

The most significant change in 2026 is regulatory. The direction is consistent across markets: operators must know their customers and their traffic, block what they can and share what they know. The status below is as of late September 2026.

  • United Kingdom. In July, Ofcom finalised rules requiring mobile providers to block numbers and messages used by scammers, set volume limits on pay-as-you-go SIMs, run know-your-customer and know-your-traffic checks on business message senders and corroborate alphanumeric sender IDs; it also told operators to withhold caller ID on calls that appear to come from UK mobiles roaming abroad unless they can be verified5. Operators already block an estimated 600 million-plus scam messages a year5. In September, industry guidance developed with the Home Office, Ofcom and the Information Commissioner’s Office clarified when providers may lawfully share fraud data with other operators, law enforcement and banks7.
  • Australia. Treasury released draft Scams Prevention Framework codes in May 2026, including a sector code for telcos that requires identity verification before services are supplied. Obligations backed by civil penalties are set to commence by at least 31 March 2027, and a proposed dispute-resolution model would split liability equally between entities in breach8.
  • European Union. The Payment Services Regulation, provisionally agreed in late 2025, treats bank-impersonation fraud as unauthorised for reimbursement purposes and introduces a duty for electronic communications providers to cooperate with payment providers on fraud prevention; publication in the Official Journal was expected around mid-20269.
  • United States. In April 2026 the FCC proposed tighter know-your-customer obligations for originating voice providers, with penalties potentially assessed per illegal call11.

Operator–bank data sharing is where the value is

Operators cannot see inside encrypted messaging apps or read call content, but they can see the signals that precede a scam: unusual calling patterns, high-volume messaging, suspicious infrastructure, abnormal roaming and recent SIM changes12. Shared in real time with banks, those signals change outcomes. The Scam Signal service, which combines network intelligence with bank transaction data through APIs, went live in South Africa in October 2025 as its second market after the UK; UK deployments have delivered detection improvements of up to 40% with a false-positive ratio of 3:1 for certain strategies10.

An operating agenda for 2027

Three priorities follow. First, close the identity gaps: SIM swap, eSIM activation and porting should carry the same step-up controls a bank applies to a new payee. Second, build the evidence trail regulators will ask for, including blocking volumes, response times and customer-verification outcomes, from the same data used to detect fraud. Third, turn network signals into services for banks, priced on avoided loss, with privacy by design so that sharing stays lawful.

For executives

What this means for your operator

  1. Map every obligation in Ofcom’s messaging rules, Australia’s telco code and the EU cooperation duty to a named owner, control and metric.
  2. Apply step-up authentication and cooling-off periods to SIM swap, eSIM transfer and porting requests.
  3. Unify call-record, signalling, SIM-lifecycle and messaging data so that detection and regulatory evidence come from one source.
  4. Launch or join operator–bank signal sharing (SIM swap, number verification, active-call risk) with documented lawful bases.
  5. Upskill fraud teams on AI tooling and model governance; more than half describe themselves as beginners1.
Put it to work

How DaasLabs can help

Run SIM-swap, IRSF, Wangiri and SIM-box detection in the SENTINEL command centre

Open the SENTINEL command centre

Deploy real-time fraud and authorisation monitoring

See real-time fraud scoring

Build an auditable evidence trail for scam-prevention obligations

See compliance & data lineage

Put supervised AI agents on alert triage and case preparation

Meet the digital workforce

Sources

  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
  7. 7
  8. 8
  9. 9
  10. 10
  11. 11
  12. 12

Figures are drawn from the cited public sources. Opinions labelled “DaasLabs point of view” are our own.

Where this fits in the story

From connectivity provider to intelligent, AI-native operator

This piece is chapter 4 of 6: the proof. Seven working accelerators — led by the SENTINEL fraud and revenue-assurance command centre.

  1. 01 The pressure 2 insights
  2. 02 The value chain 3 insights
  3. 03 The foundation 2 insights
  4. 04 The proof 2 insights
  5. 05 The workforce 3 insights
  6. 06 The journey Tools
Stay informed

Get new telecom insights in your inbox

New perspectives on AI, data and transformation in telecom — a few times a month. Browse all insights.

AI
AI Analyst

I'm the DaasLabs AI Analyst for the telecom demo platform. I can help with:

  • Revenue assurance & CDR reconciliation
  • Fraud: SIM swap, SIM box, IRSF and Wangiri
  • Churn, customer and network analytics
  • Executive briefings across the accelerators

Answers are generated from the demo data.