ScamAI raised $2.6M to combat AI-powered scams
scam.ai

Industries

Telecom fraud detection

Protect SIM changes, account access, and support channels from synthetic identities and social engineering.

$39B

estimated annual global losses to telecom fraudSource: CFCA Global Fraud Loss Survey

  • Liveness on high-risk account changes
  • Document forensics in account recovery
  • Stop SIM-swap social engineering

Where telecom gets hit

A SIM swap starts with a story: an attacker armed with breached personal data talks a support rep or retail associate into moving a victim's number, then intercepts the one-time codes protecting their bank, email, and crypto accounts. Port-out fraud, account-recovery takeovers, and synthetic identities at activation follow the same pattern — the human check is the weakest link.

How ScamAI helps

ScamAI re-verifies the customer is live and real on high-risk changes — a face-liveness check the fraudster on the line can't pass — and surfaces device and document risk signals before a SIM or account moves.

The FCC has rewritten the SIM-swap playbook

The FCC's 2023 rules on SIM swapping and port-out fraud require wireless providers to authenticate customers securely before processing a SIM change or number port, and to notify the customer immediately — flexible on method, accountable for outcomes. They sit on top of long-standing CPNI obligations penalizing weak account-access controls, leaving one open question: what "secure authentication" means once generative AI defeats knowledge-based checks and naive photo review. ScamAI's answer interrogates the media itself — face liveness and deepfake screening on high-risk changes, document forensics on forged IDs in recovery flows.

Where detection sits in the SIM-change flow

The same entry points recur across the CFCA's estimated $39B in annual telecom fraud losses: SIM swaps, number ports, account recovery, and new-line activation. When a SIM change or port-out arrives — in-app, in store, or through support — the flow triggers a step-up face check screened by Eva V1.6 for deepfakes and presentation attacks, while identity documents in recovery flows get forensic scoring, so a forged ID fails however polished the story. The REST API drops into order-management and support flows, and the customer notification the FCC requires stays — detection makes the approval behind it trustworthy.

/ROI

What this is worth

  • Loss avoidance: as an illustration, at 50,000 checks a month, catching just 0.2% more synthetic media is ~100 frauds stopped — at a $10k average loss, that's ~$1M a month that never walks out the door.
  • Review time: evidence-backed results cut manual review from minutes to seconds, so analysts handle the small flagged fraction instead of screening everything.
  • Compliance posture: explainable, auditable results give regulators and auditors evidence, not a black-box score.

Common questions

How can carriers prevent SIM-swap fraud?

By making the authentication step before a SIM change resistant to the attacks in use. Knowledge-based questions fail because answers leak in breaches; SMS codes fail because the attacker captures the number. The durable control verifies the person: a face check screened for deepfakes and presentation attacks, in the carrier's app or on a retail tablet, plus document forensics on IDs in recovery flows. With the customer notifications the FCC now requires, that closes the social-engineering path into someone's number.

What do the FCC's SIM-swap rules require of wireless providers?

The FCC's 2023 rules require wireless carriers to use secure methods to authenticate a customer before executing a SIM change or port-out, to notify the customer immediately on any such request, and to maintain processes for failed authentication and complaints. The rules deliberately avoid prescribing one technology; carriers choose methods that resist current attacks. That flexibility is why providers add face-based verification with deepfake screening on high-risk changes: its strength does not depend on secrets the attacker already holds.

Can identity verification with deepfake detection run in retail stores and the carrier app?

Yes, and covering both matters, because fraudsters route to the weakest path. In the app, the SIM-change or recovery flow triggers a face capture that Eva V1.6 screens for deepfakes and presentation attacks before the request proceeds. In stores, the same verification runs on the retail tablet, so a walk-in with a forged ID faces the same check as a remote attacker. The on-device agent runs detection locally on the tablet or phone, keeping biometric media on the endpoint.

See ScamAI on Telecom fraud detection

15 minutes, on your own media. Pick a slot and leave with a result.