Fraud has moved from a leakage line to a duty of care.
Criminals use the network itself — swapping SIMs to steal one-time passcodes, pumping traffic to premium ranges, routing calls through SIM boxes. Regulators now expect operators to block, verify and prove they did. SENTINEL is the DaasLabs fraud and revenue-assurance command centre: supervised AI agents run an observe–orient–decide–act loop on governed CDR, SIM and billing data, and named analysts approve every exception.
global telecom fraud losses in 2025, up from $38.95bn in 2023
Seven threats, one command centre
What each attack looks like on an operator network, the signal SENTINEL watches, and who carries the loss.
SIM swap & account takeover
A fraudster ports the victim's number to a new SIM, then intercepts OTPs for wallets and bank apps.
IRSF
Traffic is pumped to high-cost international ranges; the operator pays out before the bill is ever collected.
Wangiri
One-ring missed calls lure customers to call back a premium number.
SIM box & bypass
International calls are terminated as local traffic through banks of SIMs, skipping interconnect fees.
Scams & smishing
Spoofed calls and phishing texts impersonate banks, couriers and the operator itself.
Subscription & device fraud
Synthetic identities take handsets and plans with no intent to pay; cloned IMEIs hide stolen devices.
Revenue-assurance leakage
Usage that is never rated or billed, wrong tariffs and interconnect mismatches — no attacker needed.
One team, one case file
Fraud, revenue assurance and security work the same cases on the same governed data — no hand-offs between tools.
Revenue Assurance & Fraud service →How a case moves: observe, orient, decide, act
Agents do the routine work end to end. Policy decides what goes straight through; people approve the rest. Live counts from the demo pipeline.
Observe
CDRs, SIM-swap and port events, IMEI changes, billing adjustments and complaints stream in from the governed data fabric.
Orient
Each signal is enriched with subscriber, device and usage context, scored for risk and classified by threat type.
Decide
Within policy, the playbook applies. Outside it, the case lands in a named analyst's queue with the agent's evidence and rationale.
Act
Block the SIM, hold the swap, freeze the linked wallet, credit the customer or escalate — with SLA tracking.
What the command centre shows
Five things a fraud or RA lead reads first in the console below.
Pipeline & throughput
Cases at each OODA stage, events per second, latency and SLA breaches.
2Exposure
Money at risk now, by severity and by threat type.
3Critical cases
The highest-risk subscribers, one click from the investigation workbench.
4Active threats
Case counts and exposure for each fraud vector.
5Countermeasures
Immediate blocks, short-term controls and the strategic roadmap.
Live command centre
Running on a synthetic, anonymised demo dataset of about one million network events. Figures are illustrative, not client results.
OODA Pipeline
Real-time case progression through Observe → Orient → Decide → Act → FeedbackAlert Volume (24h)
Alerts detected vs blockedRisk Distribution
By severity levelFraud by Category
Cases by fraud vectorCFO view: exposure by threat
Current exposure ₱2.46MDemo data. One threat type carries almost nine-tenths of the money at risk, so it gets the first controls.
Critical Cases Requiring Action
39 cases| Case ID | Type | Risk | Exposure | Action |
|---|---|---|---|---|
| SUB-102960 | SIM Swap | 94.6 | ₱735 | |
| SUB-108905 | ATO | 94.4 | ₱11,548 | |
| 639262724773 | SIM Box | 94.3 | ₱11,340 | |
| SUB-103524 | SIM Swap | 94.4 | ₱1,600 | |
| 639064618428 | Wangiri | 82.4 | ₱3,692 |
Real-Time Activity Feed
LIVE-
Critical SIM swap detected — SUB-102960 flagged for immediate review2 min ago
-
IMEI cloning pattern — 5 MSISDNs sharing IMEI 4788034298324655 min ago
-
Case OODA-1847 closed — SIM blocked, recovery initiated8 min ago
-
ML model retrained — IsolationForest updated with 250 new anomalies15 min ago
-
Wangiri pattern detected — 639157287843 with 48.9% short-call rate18 min ago
-
Impossible travel detected — two cell sites 570 km apart within 59 min22 min ago
-
Auto-action triggered — linked mobile-wallet hold for high-risk SIM swap25 min ago
Active Fraud Vectors
AI analyst brief
AI is analyzing fraud patterns...
Immediate Actions
4 actions- Block critical SIM box MSISDNs (1 case)
- 24hr hold on high-risk SIM swaps (63 cases)
- Block flagged IMEIs (20 cases)
- Suspend first-party fraud indicators (1 case)
Short-Term (2-8 weeks)
4 actions- Real-time velocity caps (30/hr)
- Biometric verification for SIM swaps
- Dual-approval for credits >₱5K
- 24-hour mobile-wallet cooling period after a swap
Strategic Initiatives
Roadmap- Industry IRSF hot-list and number-range feeds
- ML real-time fraud scoring
- SS7 firewall + Diameter Edge
- Central device-register (CEIR) integration with the regulator