info This content is available in English only.
close

5 Ways Subscription Fraud Attacks Telcos - and How to Fight Back

Criminals are exploiting subscription fraud and using it as a gateway to other crimes - here's FICO's advice on how to stop it

Though subscription fraud may not be the most common type of fraud that communications service providers suffer any longer, the problem has continued to grow with global telecom fraud losses estimated to $41.82 billion in 2025, up from $38.95 billion in 2023, according to CFCA’s 2025 Global Fraud Loss Survey.


Key Takeaways

  • Global telecom fraud losses reached $41.82 billion in 2025, up from $38.95 billion in 2023, according to CFCA's 2025 Global Fraud Loss Survey. Subscription fraud remains a meaningful share of that total and keeps growing as a gateway into broader identity fraud.
  • Subscription fraud often serves as the entry point for larger identity fraud schemes. A synthetic identity used to open a fraudulent mobile subscription can become the anchor for fraudulent bank accounts, credit cards, and loans across multiple institutions.
  • Bad debt classification hides significant fraud losses. CFCA's 2025 survey estimates $5.31 billion in losses from true or stolen identity subscription fraud and $4.89 billion from first-party fraud. These figures likely understate the real scope when CSPs lack systems to separate fraud from ordinary nonpayment.
  • Expanding IoT and eSIM adoption are creating new attack surfaces. With global eSIM connections projected to grow to 1.5 billion in 2026, SIM swap fraud increasingly exposes the personal bank accounts tied to a stolen phone number.
  • Generative AI is accelerating fraud sophistication faster than most security teams can respond. CFCA reports that three-quarters of telecom decision-makers now use machine learning or AI in fraud detection, yet 84% rate their own AI expertise as only beginner or intermediate.

Subscription fraud can be a symptom of, or gateway to, other frauds. For example, a synthetic identity could be used to create a fraudulent subscription. This in turn helps build a false identity associated with a mobile number. These are then used to defraud multiple banks with fraudulent accounts, credit cards, and loans. But subscription fraud also continues in traditional ways, like those who subscribe with no intent to pay, and those who seek to acquire incentivized devices falsely just to sell them online at a profit.

Here are five other ways crooks use subscription fraud to commit crimes against customers and service providers, with advice on how to stop them.

1. Fraud Masquerades as Bad Debt

There exists in the telecom fraud world a sort of purgatory where fraudsters disguise themselves as bad debtors. In 2025, CFCA’s survey showed that the monetary loss from subscription fraud through true or stolen identity was estimated to $5.31 billion, while loss from first-party subscription fraud (with no intent to pay) was estimated to $4.89 billion.

This estimate may be conservative, though. If Communications Service Providers (CSPs) define bad debt the same way or lack programs to differentiate fraud, like synthetic identity fraud, fraud losses could be categorized as bad debt. That means fraud won't be investigated or stopped. As a result, scammers can return repeatedly to different CSPs with different types of identity frauds with little concern of being caught.

FICO’s advice: CSPs should adopt fraud management systems leveraging automated analytics instead of traditional rules-based solutions. A CFCA survey shows that 100% of operators have already adopted fraud management systems using some form of automation, validating this shift in the industry. These automated systems help CSPs define and identify different types of subscription fraud, which enables them to differentiate fraud from bad debt. More critically, automated analytics detect patterns and data linkages across subscriptions to identify and stop fraud rings that reuse stolen and synthetic identities. This prevents crimes that would otherwise remain undetected.

2. Frauds Hide among False Positives

Earlier fraudsters exploited the fact that CSPs did not traditionally share fraud data with each other. However, CFCA’s 2025 survey shows five out of six operators now integrate third-party tools into their fraud management platforms.

FICO’s advice: CSPs should pair modern, analytics-based fraud management systems with greater industry-wide data sharing to evolve fraud models that stay ahead of the crooks and close the blind spots crooks currently exploit between CSPs. Yet the CFCA 2025 survey found only 46% of operators are very willing to share intelligence incident reports, fraudulent numbers, IMEIs, and fraud alerts with industry forums. Since the same fraud rings often hit multiple CSPs, closing this gap is critical to prevent repetitive losses.

3. Internet of Things (IoT) Increases Fraud Opportunities

DDoS attacks, abuse of unlimited data services and SIM swaps are the most common ways IoT devices are being used to commit fraud. This means fraudsters have a near free-for-all before them, with an insufficiently defended yet expanding IoT attack surface. This surface can enable some of the most damaging crimes, like when SIM swaps are used to take over personal bank accounts. In 2026, global eSIM connections are also estimated to grow to 30%, from 1.2 billion to 1.5 billion. Once provisioning happens over the air, the handset stops being the only thing worth taking. The number itself becomes the asset, and the account that controls it becomes the way in.

FICO’s advice: CSP fraud teams will benefit from better defensive tools in the battle against the fraud opportunities IoT can enable. Given the scale, complexity, and interconnectedness across operators inherent to the IoT, machine learning, AI, automation, and third-party data insights are crucial to modern FMS practices in this evolving and extremely vulnerable environment.

4. Fraud Management Roles Expand, Exposing Siloed Data and Processes to Fraud

Back-office inefficiency and siloed systems are contributing to rising fraud losses. Sales and marketing, credit risk, fraud and collections are frequently operating different systems. Each collects valuable information, but the data is rarely shared across departments. This creates two problems for fraud teams: they may make improperly informed fraud decisions, and they may create experiential friction by prodding customers for duplicate information another group in the organization has collected already.

Fraud teams are also involved in a wider range of responsibilities. The CFCA reports that 16% of operators believe they cover less than 50% of the business operations within their fraud teams. This suggests that other departmental priorities are taking precedence, or a significant amount of risk is unaccounted for. The limited access to siloed information becomes a barrier for the fraud managers in doing their expanding job well.

This siloed thinking can be compounded when the different departments have opposing objectives, as can be the case for sales and fraud management. Salespeople are incentivized to close business while fraud departments work to prevent fraudsters using the sales process and marketing incentives to steal subscriptions and devices. Because it is counterproductive to turn salespeople into fraud experts, built-in real-time fraud controls are needed in the sales process to sustain the balance between maximizing sales and minimizing fraud.

FICO’s advice: CSPs should bring disparate systems together through FICO® Platform rather than pursue a rip-and-replace approach, which isn't feasible. FICO Platform dynamically connects 360-degree customer profiles to millisecond decision-making at enterprise scale, breaking down silos so organizations can share features, insights, and strategies across the entire enterprise. This lets CSPs spot cross-channel patterns that fragmented systems can't perceive, while applying consistent fraud risk approaches everywhere customers interact. Over time, the platform capabilities used to address fraud can expand to manage more use cases, like originations and the broader customer lifecycle.

5. Streaming Opens a New Fraud Vector

CSPs worldwide have pursued the ability to offer multi-play services for the better part of a decade as they have transitioned their businesses to focus on broadband and content rather than communications alone. But as the content market has moved, so have the consumption models, which means streaming is now taking over as customers’ preferred way to access video content.

Major streaming services – Netflix in particular – have often done little to prevent customers from violating their user agreements by sharing their passwords with non-subscribers. So long as the streaming brand is in customer acquisition and brand-building mode, this method of guerilla marketing made sense. As these markets mature, however, and begin to reach saturation, revenue assurance comes into focus and therefore so does subscription fraud. Suddenly, being lenient about password sharing can become a barrier to revenue growth, which in turn has negative impacts on stock prices and valuations when streamers miss their subscriber addition targets. 

FICO advice: New types of fraud can be fast-moving and can take on entirely different profiles than traditional fraud – password sharing being just such an example. Expanding the ability to monitor for fraudulent or abusive usage, alongside data sharing with other CSPs to identify patterns and repeat offenders, and to analyze those new data sets rapidly is becoming table stakes in the ongoing battles against fraud and for subscribers who want streaming in their CSP broadband and entertainment mix.

How Generative AI Is Escalating the Fraud Arms Race

Generative AI has become fraudsters' newest force multiplier. CFCA's 2025 Global Fraud Loss Survey found bad actors increasingly use generative AI to enhance the realism of voice and text-based fraud, making scams harder to detect and more damaging to operators and subscribers alike. Voice cloning can now convincingly mimic a real customer in seconds, undermining call-center verification built around older technology.

Operators are racing to close the gap — three-quarters of telecom decision-makers now use machine learning or AI in fraud detection, sharply up from 2023. But adoption has outpaced expertise: 84% rate themselves only beginner or intermediate in AI knowledge, and fraud staff are juggling 2.5 additional roles on average. CSPs are deploying AI faster than they can tune it, just as fraudsters turn the same technology against them.

FICO's advice: Fighting AI with under-resourced, under-trained deployments isn't sustainable. CSPs need interpretable, battle-tested AI. FICO Falcon Fraud Manager and FICO Platform apply consortium-trained, explainable models so fraud teams can act on what's flagged without becoming AI specialists themselves. 

Jersey Telecom's Scam Signal solution with FICO, using real-time telephony signals to detect scams, decreased fraud losses from scams by 44% and won Best Anti-Fraud Solution at the 2024 Credit & Collections Technology Awards — proof that proven AI layered onto existing infrastructure beats a from-scratch build.

Subscription fraud keeps evolving — from bad debt disguises to AI-driven voice cloning — but so do the tools to fight it. Modern, explainable analytics turn fragmented signals into early warnings, protecting revenue, customer trust, and long-term loyalty without compromising the experience.

How FICO Can Help You Stop Subscription Fraud

This is an update of a post from 2023


Frequently Asked Questions

Effective fraud programs measure more than blocked applications. Fraud and security teams should track the false positive rate on flagged subscriptions, since high rates signal lost revenue from rejected good customers. Time to detection matters just as much, showing how quickly a fraud ring gets identified after its first fraudulent subscription. Recovery rate on identified fraud losses indicates how much of the confirmed fraud amount is later collected or written off. Finally, tracking the share of fraud losses currently misclassified as bad debt gives fraud teams a baseline for how much risk stays hidden in existing reporting.

Start by sampling write-off accounts and running them through identity verification and device-linkage checks used for new applications. Accounts tied to synthetic identities, reused device IMEIs, or clusters of shared personal details typically indicate fraud rather than genuine nonpayment. Automated link analysis across the full subscriber base, rather than manual case-by-case review, scales this audit and surfaces fraud rings operating across multiple accounts. Fraud and security teams that run this audit regularly typically find a meaningful share of bad debt is actually unreported fraud, giving finance and fraud teams a more accurate view of true losses.

The strongest approach embeds fraud controls directly into the sales and onboarding workflow rather than adding separate review steps afterward. Real-time fraud risk scoring at the point of application lets low-risk customers move through instantly while only genuinely suspicious applications trigger added verification. This keeps friction targeted rather than universal, so legitimate customers rarely notice the fraud check. Because salespeople are incentivized to close deals rather than evaluate risk, the controls need to run automatically in the background rather than depend on sales staff spotting red flags themselves.

Fraud rings reuse the same stolen and synthetic identities across telecom, banking, and other sectors, so isolated defenses only catch part of the pattern. CFCA's 2025 Global Fraud Loss Survey found just 46% of operators are very willing to share fraud intelligence like incident reports, fraudulent numbers, and IMEIs with industry forums, leaving major gaps. Fraud and security teams that participate in cross-industry data consortiums and align fraud definitions with banking partners can flag a synthetic identity the first time it appears, rather than after it has already opened accounts at multiple institutions.

chevron_left Blog home
RELATED POSTS

Take the next step

Connect with FICO for answers to all your product and solution questions. Interested in becoming a business partner? Contact us to learn more. We look forward to hearing from you.