How to Fight Telecommunications Subscription Fraud in the Age of AI

As synthetic identity fraud and eSIM reshape telecom risk, identity-led analytics keep fraud teams ahead of account takeovers and fake profiles

Subscription fraud has always had a straightforward economic logic. The device drove the resale value, so taking the value out of the handset took much of the value out of the fraud. Two developments are now weakening that logic, and telecoms whose controls still rest on it are increasingly defending against an out-of-date model of the crime.


Key Takeaways

  • The fraud target has shifted from devices to identities. Synthetic identity fraud and eSIM provisioning mean the handset no longer drives resale value, the subscription and account access do.
  • Telecom fraud attacks are outpacing other industries. LexisNexis Risk Solutions found 5.2% of digital interactions in telecoms were confirmed fraud in 2025, higher than ecommerce (4.6%) and five times the fraud ratio in financial services.
  • Falling fraud filings mask a tactical shift, not less harm. Cifas reports a 24% drop in telecom identity fraud filings, driven by criminals moving from new-account fraud to account takeovers, particularly on mobile accounts.
  • An identity-led model only works with clear ownership. Before deploying new controls, telcos need an agreed answer to who owns subscription fraud risk (fraud, credit risk, or revenue assurance) and an executive-sponsored risk appetite.
  • Three controls matter most now: adaptive machine learning over static scorecards, early warning monitoring that continues after activation, and link analysis run across the full account lifecycle, not just at application.

What Are the Two Shifts That Have Moved the Subscription Fraud Target?

The first is the industrialization of synthetic identity fraud. Cifas reports that criminals are building convincing long-term synthetic profiles that blur the line between real users and AI-generated imposters. LexisNexis Risk Solutions, analyzing 116 billion transactions during 2025, found synthetic identity fraud rose eight-fold year-on-year to 11% of all global fraud attacks; while this is a cross-sector figure rather than a telecom one, it shows the urgency of this trend. A stolen identity has a real victim who eventually notices and disputes. A fabricated one has nobody: no one to trace a device back to, no one to blacklist, and no dispute that closes the loop.

The second is eSIM. Global eSIM connections are on track to grow 30% in 2026, from 1.2 billion to 1.5 billion.Once provisioning happens over the air, the handset stops being the only thing worth taking. The number itself becomes the asset, and the account that controls it becomes the way in.

The Evolution of Fraud in the Telco Industry: What the Filing Data Shows

LexisNexis Risk Solutions found that 5.2% of digital interactions in the telecoms sector were a confirmed fraud attack in 2025, a higher rate than ecommerce at 4.6% and five times higher than financial services. The attacks concentrate at new account creation, where roughly one in eight attempts is fraudulent, and at payments, where attack volume rose 84% year on year.

Identity fraud filings from the telecom sector fell 24% over the same period, the largest drop of any sector. Cifas attributes this not to a reduction in harm but to a shift in criminal tactics, with fraudsters increasingly targeting account takeovers, particularly against mobile phone accounts. The fraud has not receded. It has moved from opening accounts to taking over existing ones.

The practical consequence is that controls anchored at the point of fulfillment will catch progressively less fraud. The decision has to move upstream to the application, and then keep running after the account goes live.

Fernando Lopez on Subscription Fraud

 

Who Is Accountable for Subscription Fraud? 

Before any of that, telecoms should determine who owns and is accountable for subscription fraud. Is it the fraud team? Credit risk? Revenue assurance? Is there a clear and agreed fraud risk appetite that has executive sponsorship and is agreed by all stakeholders? An identity-led model only works when someone owns the identity.

Industry data sharing matters for the same reason. There are numerous examples of the industry coming together to share data on known fraud threats and profiles to mitigate the impact of fraudulent activity. Data sharing for these purposes should be non-competitive, but it still relies on a common definition of what data to share, where to host it securely, how regularly it is updated, and what mechanisms are available to access the consortium data.

Three Analytical Priorities for the Near Future

Once those questions have clear answers, analytical techniques can substantially reduce and prevent subscription fraud losses. Three matter more now than they did three years ago.

  • Adaptive models rather than scorecards. While the scorecard approach is tried and tested, the time required to develop the score means that by the time it is operationalized the fraud MO has changed. Machine learning techniques are scalable, self-learning and adaptive. Algorithms such as neural networks can understand hidden layers within the relationships between variables, which is what allows them to surface the quiet inconsistencies characteristic of a fabricated identity.
  • Early warning that keeps learning. Once activated, the early usage of a new subscription can be monitored for warning signals of fraudulent activity: zero usage in the first few days after an order is fulfilled, for instance. These alerts have traditionally been deployed by rules-based systems, which are effective to a point, but dependency on rules introduces latency and rulesets can quickly become obsolete. Adaptive machine learning identifies changing patterns and prioritizes alerts, enabling fraud teams to make efficient use of analysts’ time.
  • Link analysis across the whole lifecycle. Link analysis has always been the counter to organized rings, whose biggest weakness is shared identity data. Fuzzy matching and relationship-driven predictive analytics turn one uncovered case into many, and visualization techniques significantly reduce the time taken to unpick a ring. What has changed is that the same shared-data fingerprints now appear in SIM swap and takeover events after the point of sale. Running link analysis only at the pre-book stage overlooks half the signal.

Pulling It Together: The Three Controls That Work Against Subscription Fraud in the Age of AI

An identity-led approach starts with the data. Internal and external sources need to come into a single view at the point of application. That changes the question being asked. Instead of ‘is this application complete and plausible?’, the check becomes ‘does this identity exist, and does it behave like the person it claims to be?’

That view cannot stop at the sale. It has to carry on after activation, monitoring for sleeper behavior rather than closing the case at fulfillment.

Entity resolution and network analytics do the rest. Together they expose the links across applications and accounts that reveal a ring. Organized groups reuse addresses, devices, bank details and contact points, because they have little choice. Run that analysis across new applications and live accounts, and one confirmed case becomes the whole cluster.

The controls that have always worked against subscription fraud still work: clear ownership, adaptive machine learning and link analysis. They simply have to be pointed at the identity rather than the handset.

How FICO Is Helping Telcos 

Note: This is an update of a post from 2023.


Frequently Asked Questions

New-account subscription fraud happens at the application stage, when a criminal uses a stolen or synthetic identity to open a subscription that was never authorized. Account takeover happens after a legitimate subscription is already active, when a fraudster gains control of an existing account, often through social engineering, credential theft, or SIM swap, and redirects its value away from the real owner. Cifas attributes the drop in telecom identity fraud filings to this shift, noting fraudsters are increasingly targeting account takeovers rather than new applications. The distinction matters because controls built for the application stage rarely catch fraud that surfaces after activation.

Identity-led fraud prevention does not have to add friction to onboarding. Rather than asking applicants to submit more documents, it combines internal and external data at the point of application to answer a sharper question: does this identity exist, and does it behave the way the person it claims to be would behave? Because the analysis runs in the background against existing data sources, legitimate customers pass through the same application flow they always have, while fabricated or high-risk identities get flagged for review. The result is fraud detection that scales without adding steps for the majority of applicants who are exactly who they say they are.

ROI for an identity-led fraud strategy is best measured across three areas rather than a single number:

  1. Losses prevented at both new-account and account-takeover stages, compared against a pre-implementation baseline
  2. Filing and dispute reduction, since fewer viable synthetic identities mean fewer accounts that require write-off or recovery effort
  3. Operational efficiency: adaptive models and prioritized alerts reduce the manual review volume fraud analysts handle, freeing their time for the cases that matter most. 

Providers that track all three see a clearer picture than those measuring blocked applications alone.

chevron_left Blog home
RELATED POSTS

Take the next step

Connect with FICO for answers to all your product and solution questions. Interested in becoming a business partner? Contact us to learn more. We look forward to hearing from you.