Fraud Command Centre

Fraud Analyst Admin
Chapter 4 · The proof  SENTINEL accelerator

Fraud has moved from a leakage line to a duty of care.

Criminals use the network itself — swapping SIMs to steal one-time passcodes, pumping traffic to premium ranges, routing calls through SIM boxes. Regulators now expect operators to block, verify and prove they did. SENTINEL is the DaasLabs fraud and revenue-assurance command centre: supervised AI agents run an observe–orient–decide–act loop on governed CDR, SIM and billing data, and named analysts approve every exception.

$41.8bn

global telecom fraud losses in 2025, up from $38.95bn in 2023

Source: CFCA Global Fraud Loss Survey, 2025
Find it in the monthly reportStop it while the call is live Sampled RA checksFull-population controls Analysts triage everythingAgents triage, people decide

Seven threats, one command centre

What each attack looks like on an operator network, the signal SENTINEL watches, and who carries the loss.

Live command centre

Running on a synthetic, anonymised demo dataset of about one million network events. Figures are illustrative, not client results.

Demo data

Fraud & revenue-assurance command centre

Detect, investigate and act on fraud and leakage cases through the OODA pipeline

42 Critical
OODA Pipeline
Real-time case progression through Observe → Orient → Decide → Act → Feedback
12.5K
Events/sec
42ms
Avg Latency
69
Active Cases
58
Blocked Today
99.2%
Model Accuracy
0
SLA Breaches
12%
69
Total Cases
42 / 95
Critical / High
immediate action
₱2.46M
Exposure at Risk
0.3%
99.2%
Detection Rate
122
OODA Open Cases
in pipeline
2.1%
84.1%
Blocked Rate
Alert Volume (24h)
Alerts detected vs blocked
Risk Distribution
By severity level
Critical: 42
High: 95
Elevated: 63
Moderate: 74
Fraud by Category
Cases by fraud vector
CFO view: exposure by threat
Current exposure ₱2.46M
SIM swap & account takeover₱2.2M
SIM box & interconnect bypass₱129K
Wangiri₱44K
IRSF₱27K
Behavioural anomaly₱24K
IMEI cloning & device spoofing₱9K

Demo data. One threat type carries almost nine-tenths of the money at risk, so it gets the first controls.

Critical Cases Requiring Action
39 cases
Case ID Type Risk Exposure Action
SUB-102960 SIM Swap 94.6 ₱735
SUB-108905 ATO 94.4 ₱11,548
639262724773 SIM Box 94.3 ₱11,340
SUB-103524 SIM Swap 94.4 ₱1,600
639064618428 Wangiri 82.4 ₱3,692
Real-Time Activity Feed
LIVE
  • Critical SIM swap detected — SUB-102960 flagged for immediate review
    2 min ago
  • IMEI cloning pattern — 5 MSISDNs sharing IMEI 478803429832465
    5 min ago
  • Case OODA-1847 closed — SIM blocked, recovery initiated
    8 min ago
  • ML model retrained — IsolationForest updated with 250 new anomalies
    15 min ago
  • Wangiri pattern detected — 639157287843 with 48.9% short-call rate
    18 min ago
  • Impossible travel detected — two cell sites 570 km apart within 59 min
    22 min ago
  • Auto-action triggered — linked mobile-wallet hold for high-risk SIM swap
    25 min ago

Active Fraud Vectors

Account Takeover / SIM Swap
86 cases • ₱2.2M exposure
Critical
37
Critical
26
High
23
Elevated
SIM Box / Interconnect Bypass
22 cases • ₱129K exposure
High
1
Critical
17
High
3
Elevated
Wangiri (One-Ring Fraud)
12 cases • ₱44K exposure
High
1
Critical
11
High
0
Elevated
Behavioral Anomaly
36 cases • ₱24K exposure
Elevated
0
Critical
10
Elevated
26
Moderate
IRSF (International Revenue Share)
8 cases • ₱27K exposure
High
0
Critical
7
High
1
Elevated
IMEI Cloning / Device Spoofing
20 cases • ₱9K exposure
Elevated
0
Critical
12
High
8
Elevated
AI analyst brief
Analyst brief · demo data

AI is analyzing fraud patterns...

Immediate Actions
4 actions
  • Block critical SIM box MSISDNs (1 case)
  • 24hr hold on high-risk SIM swaps (63 cases)
  • Block flagged IMEIs (20 cases)
  • Suspend first-party fraud indicators (1 case)
Short-Term (2-8 weeks)
4 actions
  • Real-time velocity caps (30/hr)
  • Biometric verification for SIM swaps
  • Dual-approval for credits >₱5K
  • 24-hour mobile-wallet cooling period after a swap
Strategic Initiatives
Roadmap
  • Industry IRSF hot-list and number-range feeds
  • ML real-time fraud scoring
  • SS7 firewall + Diameter Edge
  • Central device-register (CEIR) integration with the regulator
AI
Fraud AI Analyst

Fraud AI Analyst ready to assist with:

  • Case investigation & evidence analysis
  • Pattern detection & anomaly explanation
  • Recommended actions & countermeasures
  • Financial impact assessment