RAFM 2024 (1)

 

In 2024, an estimated $1.3 trillion was stolen globally as a result of scam operations. The scale of the problem is staggering, with recent research indicating that 57% of adults experienced a scam in a 12-month period, and 23% of that audience lost money.

Despite heavy investments in SMS firewalls, telecom operators continue to see these malicious messages reach their subscribers. In our recent webinar, The Invisible Threat Bypassing Core Firewalls, experts from LATRO and Halotel Tanzania sat down to dissect the technical realities of modern scam operations and how signaling intelligence is closing the visibility gap.

Here are the key takeaways from the session.

 

The Business Cost: Trust as an EBITDA Driver  

For the financial and executive leadership of an operator, the cost of scam traffic is multi-layered. Nagib Ferej, Deputy CFO of Halotel Tanzania, emphasized that while there is direct revenue leakage and increased operational costs from investigations and customer support, the most severe impact is reputational.

"The biggest cost is not the scam itself, it's the loss of customer trust," Ferej explained. When a message comes through the network, customers associate the experience with the operator, regardless of where the scam originated. This trust deficit is a critical risk for operators expanding into digital financial services. If the underlying communication layer is compromised by SMS scams, the financial layer—such as mobile money wallets—is directly at risk for social engineering and unauthorized access.

Social Media Post (33)-3

 Protecting the Enterprise Relationship The financial impact of scam traffic extends beyond the subscriber to the operator's enterprise clients. When fraudsters spoof legitimate enterprises—such as banks or digital services—it generates a flood of complaints. If an operator's firewall cannot dynamically capture the configuration of these spoofed messages, the enterprise client's brand reputation suffers. Securing the signaling layer allows operators to identify the nature of the spam and stop the impersonation at the source, thereby protecting their highly valuable B2B relationships.  

 

The Technical Blind Spot: SMS Blasters and 2G-Fallback  

If operators are constantly updating their firewalls, why are these messages getting through? The answer lies in the hardware. Fraudsters are utilizing SMS Blasters to bypass the core network entirely.

During the session, ElMehdi Erroussafi, LATRO’s Director of Solutions Architecture, clarified a common technical misconception regarding network generations. SMS Blasters act as self-operating networks. These rogue base stations capture a victim's device and force it to downgrade to a 2G connection in order to push the SMS.

Crucially, an operator does not need to have active 2G coverage to be vulnerable. As long as a subscriber's smartphone has the capability to scan a 2G network—which the majority do—an SMS Blaster can execute the fraud. Because this traffic goes directly to the subscriber and bypasses the central firewall, traditional content-based filtering cannot detect it.

Scams Are No Longer Just "Random Noise" ElMehdi also pointed out that operators are no longer facing isolated or random fraud noise. Today’s scam ecosystems are highly targeted and data-driven. Fraudsters gather extensive data profiles on victims; if a number is identified as belonging to a high-value demographic, an entire industrialized operation will repeatedly target that individual with personalized, multi-channel attacks. Because scammers rapidly rotate through thousands of SIMs to avoid reputation penalties, relying on reactive blacklisting is mathematically ineffective.

 The Power of Ecosystem Collaboration Tackling industrialized scams requires moving beyond internal silos and collaborating directly with national regulators. Nagib Ferej highlighted a powerful success story from Tanzania, where strong collaboration with the Tanzania Communication Regulatory Authority (TCRA) has been instrumental. By utilizing a shared system to track fraudulent activity, the industry successfully deactivated 47,000 SIM cards and blacklisted 39,000 associated identification documents in 2025 alone. This level of ecosystem collaboration is essential to systematically dismantle fraud operations.  

 

The Solution: Moving to the Control Plane  

Relying on Call Detail Records (CDRs) or message content for fraud detection is inherently retrospective; these records capture the outcome only after the communication has already occurred. To transition from a reactive posture to a proactive defense, operators must shift their focus to the signaling layer.

By monitoring the control plane, LATRO’s Scammer Shield processes signaling events to identify the hidden footprints of scam operations. This non-invasive approach detects anomalies in location updates and IMSI attaches before a scam message is even initiated, allowing operators to identify and track unauthorized devices like SMS Blasters and SIM farms.

Scammer Shield Presentation slides from the webinar:

 

Tackling industrialized scams requires moving beyond silos and ensuring collaboration across IT, fraud, network, and mobile money teams. By implementing a layered security approach rooted in signaling analytics, operators can protect their subscribers, defend their enterprise clients, and secure their long-term growth.

Ready to close the visibility gap in your network? * Watch the full webinar replay to hear the complete technical breakdown and frontline insights from Halotel Tanzania.

 

 

Visit the LATRO Scammer Shield product page to learn how our signaling overlay can protect your network integrity without disrupting your existing infrastructure.

Contact us for more information or a personalized consultation.