OTT Bypass vs SIM Box Fraud: Same Theft, Different Fingerprints

Both steal the same thing: the international termination rate you were owed. But OTT bypass and SIM box fraud get there by different roads, leave different fingerprints, and fall to different defences. If your fraud strategy treats them as one generic “bypass” line item, you are catching whichever one your tools happen to see. This is how to tell them apart.

The theft they share

An international call is supposed to follow the international settlement path: the caller’s carrier hands the call to the called operator, which bills an international termination rate. Bypass fraud converts that expensive international call into a cheap local one before the called operator sees it. The operator loses the international rate; the fraudster pockets the spread. The ITU-T, in its 2024 technical report on OTT bypass, put this among the largest revenue-assurance threats operators face.

SIM box fraud: the mechanical era

SIM box (or SIM bank) fraud is the older trade. Racks of GSM gateways, each slot holding a local SIM, receive calls over the internet and re-originate them as local on-net calls. To the called operator it looks like a local subscriber calling a neighbour.

Its fingerprints are mechanical and well understood: many simultaneous calls from few numbers, uniform call durations, SIMs that never sleep, roaming-like mobility patterns in fixed locations, and A-numbers that rotate in ways no human subscriber does. Detection is a mature discipline: signalling analysis, test calls and per-SIM behaviour scoring.

OTT bypass: the software era

OTT bypass replaces the SIM farm with an app. Somewhere along the path, the call is terminated into WhatsApp, Viber or a similar over-the-top service, and re-originated locally by an app instance or a software gateway. No SIM inventory, no physical footprint, and the entry cost is close to zero.

Its fingerprints live deeper in the traffic statistics, because the origination looks organic: short average call duration on specific corridors, heavy repetition of the same B-numbers, uniform A-number clusters, sudden ACD collapse, and international intent arriving as on-net traffic. Our OTT Bypass Detection Observatory walks the full methodology.

Side by side

SIM box fraudOTT bypass
Re-origination viaBanks of local SIMs in GSM gatewaysOTT apps and software gateways
FootprintPhysical: SIM inventory, racks, powerVirtual: software, disposable accounts
Classic signaturesSimultaneous calls per SIM, 24/7 activity, fixed-location “roamers”ACD collapse, B-number repetition, A-number uniformity per corridor
Best detectionSignalling analysis, SIM behaviour scoring, test callsCDR statistical baselines per corridor, test calls, expert review
Scaling costLinear: more SIMs, more boxesNear zero: software copies itself

Why the distinction matters operationally

Three reasons. First, tooling: a SIM-box-tuned detection stack will under-detect OTT bypass, because the signatures barely overlap. Second, response: SIM boxes can be hunted physically and SIMs can be blocked at the subscription level; OTT bypass has to be caught statistically and addressed commercially, corridor by corridor. Third, trajectory: SIM box fraud is a mature, pressured business, while OTT bypass rides the growth of OTT platforms themselves, which makes it the faster-growing problem in most regions.

What detection looks like when done properly

Test calls into suspect corridors, statistical CDR analytics against per-corridor baselines, and signalling inspection where available, run continuously. Expect roughly a third of machine-flagged traffic to be false positives without expert review; the machines propose, engineers confirm, thresholds recalibrate quarterly. Fraud detection is a discipline, and the discipline is the product.

Both flavours are exactly what our observatories watch every day. Start with the OTT observatory, or talk to the team about your corridors.

Leave a Reply

Your email address will not be published. Required fields are marked *