Both steal the same thing: the international termination rate you were owed. But OTT bypass and SIM box fraud get there by different roads, leave different fingerprints, and fall to different defences. If your fraud strategy treats them as one generic “bypass” line item, you are catching whichever one your tools happen to see. This is how to tell them apart.
The theft they share
An international call is supposed to follow the international settlement path: the caller’s carrier hands the call to the called operator, which bills an international termination rate. Bypass fraud converts that expensive international call into a cheap local one before the called operator sees it. The operator loses the international rate; the fraudster pockets the spread. The ITU-T, in its 2024 technical report on OTT bypass, put this among the largest revenue-assurance threats operators face.
SIM box fraud: the mechanical era
SIM box (or SIM bank) fraud is the older trade. Racks of GSM gateways, each slot holding a local SIM, receive calls over the internet and re-originate them as local on-net calls. To the called operator it looks like a local subscriber calling a neighbour.
Its fingerprints are mechanical and well understood: many simultaneous calls from few numbers, uniform call durations, SIMs that never sleep, roaming-like mobility patterns in fixed locations, and A-numbers that rotate in ways no human subscriber does. Detection is a mature discipline: signalling analysis, test calls and per-SIM behaviour scoring.
OTT bypass: the software era
OTT bypass replaces the SIM farm with an app. Somewhere along the path, the call is terminated into WhatsApp, Viber or a similar over-the-top service, and re-originated locally by an app instance or a software gateway. No SIM inventory, no physical footprint, and the entry cost is close to zero.
Its fingerprints live deeper in the traffic statistics, because the origination looks organic: short average call duration on specific corridors, heavy repetition of the same B-numbers, uniform A-number clusters, sudden ACD collapse, and international intent arriving as on-net traffic. Our OTT Bypass Detection Observatory walks the full methodology.
Side by side
| SIM box fraud | OTT bypass | |
|---|---|---|
| Re-origination via | Banks of local SIMs in GSM gateways | OTT apps and software gateways |
| Footprint | Physical: SIM inventory, racks, power | Virtual: software, disposable accounts |
| Classic signatures | Simultaneous calls per SIM, 24/7 activity, fixed-location “roamers” | ACD collapse, B-number repetition, A-number uniformity per corridor |
| Best detection | Signalling analysis, SIM behaviour scoring, test calls | CDR statistical baselines per corridor, test calls, expert review |
| Scaling cost | Linear: more SIMs, more boxes | Near zero: software copies itself |
Why the distinction matters operationally
Three reasons. First, tooling: a SIM-box-tuned detection stack will under-detect OTT bypass, because the signatures barely overlap. Second, response: SIM boxes can be hunted physically and SIMs can be blocked at the subscription level; OTT bypass has to be caught statistically and addressed commercially, corridor by corridor. Third, trajectory: SIM box fraud is a mature, pressured business, while OTT bypass rides the growth of OTT platforms themselves, which makes it the faster-growing problem in most regions.
What detection looks like when done properly
Test calls into suspect corridors, statistical CDR analytics against per-corridor baselines, and signalling inspection where available, run continuously. Expect roughly a third of machine-flagged traffic to be false positives without expert review; the machines propose, engineers confirm, thresholds recalibrate quarterly. Fraud detection is a discipline, and the discipline is the product.
Both flavours are exactly what our observatories watch every day. Start with the OTT observatory, or talk to the team about your corridors.