Zencastr
00:00:00
00:00:01
Speed1x
Format▸
Share
Embed
Report

The Intelligence Gap: Why Are Scams Still Getting Through? A conversation with Ian Matthews, Founder and CEO of Strata Labs

Scam Rangers
Scam Rangers

0 plays · Sep 30, 2026

Transcript

Speaker: If you go into your messaging client on your Android device or your Apple device, you have the ability to hit a ah button that says report as junk, report as spam. And there are millions and millions and millions and millions of messages that are reported as spam to Google and Apple. When you dig through that data and you you kind of clean up all the noise, just like any other abuse box, there's a ton of intelligence about malicious messaging, where the malicious messages are originating, what types of URLs in them, what are the callback numbers people are being asked to engage with.

Speaker: Google and Apple are undoubtedly using it to help train their AI models to build better controls on the device. So it is making it to a a a small number of organizations in the Defender ecosystem, but the intelligence is not making it to where it's most actionable, which is the financial services community.

Speaker: So in the last episode, we had a conversation about phone number intelligence with Jamie Sederstrom from Somos. And today I'm excited double click much deeper into the telco industry and what signals and intelligence we can get, but mostly talk about trust. So I'm very excited to have our scam ranger for today on the call, Ian Matthews, former founder and CEO of WMC Global.

Speaker: Welcome to scam rangers a podcast about the human side of fraud, and the people who are on a mission to protect us. I'm your host, Ayelet Bigger Levine, and I'm passionate about driving awareness and solving this problem.

Speaker: Ian, welcome to the podcast. Welcome to ScamRangers. Thank you. Thanks for having me. Great. So first of all, I would love for you to talk about your career in this industry and what your focus was and kind of your why.

Speaker: Sure. So I'm currently founder and CEO of Stratolab, which is a strategic advisory focused on the intersection of telecommunications, cybersecurity, and AI and all the resultant fraud that takes place at that intersection. um as you mentioned, I was formerly founder and CEO of WMC Global, which is a cyber threat intelligence organization um that spent a lot of time focusing on ah building bridges between the telecommunications world and everyone else and looking at how financial services and the wireless industry predominantly can work together to protect the common customer, which is the consumer.

Speaker: Right. If you look at the Venn diagram of a customer of a bank and a wireless carrier, it's a circle. um And so there's ah this vested interest in in both sides of the fence and protecting that user and their own businesses. Prior to that, I spent a number of years working in the telecommunications space in the mobile messaging interoperability space and in the premium rate billing space, um helping set up some of the pipes for mobile messaging, as well as deliver some of the early pre-smartphone mobile content.

Speaker: ah technologies and ultimately discovered that you know my real passion was in identifying the abuse of those technologies and looking at some how we could retool intelligence that was designed to drive revenue in the mobile ecosystem to protect users.

Speaker: So important. And also your new initiative, ah very timely and important as well. I'm you know spending time with professionals in the and the financial services industry and quite surprised about the gap that we have with our tooling and protections for what we think is coming, but is actually already here. when it comes to agentic commerce and and different aspects of how AI is going to be leveraged and the controls are way behind. So we definitely need that focus on an AI and the telco industry as well. So that's amazing. So but let's go back a little bit to understand kind of where we are and what what threats are. previously you were looking at your time at WMC Global. So what what are the threats that that you look to protect and what are the controls and means that you use to to do that? So if we want to go back in time a little bit with with WMC Global, um originally founded that company to focus on mobile billing fraud.

Speaker: So it was really ah focused on looking at at ah premium rate billing channels like premium SMS, like pay for it in the UK, like direct carrier billing. And in the early days, this was a really good frictionless way for um content creators, content providers to sell content to folks on their mobile device without having to have them pull out a credit card and fill out a bunch of details on the website. it was It was basically just put the charge on the the wireless bill, pay for it later.

Speaker: And um very quickly, i think we discovered that a lot of unscrupulous parties were just cramming charges onto wireless bills, um either by um not disclosing that charges existed and folks thought they would be getting things for free or for just putting charges on bills without even offering a product or service just through abusing the the billing mechanisms. And so we started by looking more deeply into that. Now that type of billing across the globe has largely died out and been replaced by, you know, the ah the the Apple App Store and the Google Play Store and and other billing mechanisms. So that largely is not a major issue as it was back in those days. But messaging over time has ah grown to be heavily abused. Scammers have discovered, just like mobile marketers have, that um text messages have a 98% open rate within 90 seconds. And so ah whatever the scam payload is, whether it's a malicious link, whether it's a callback number, whether it's a romance scam or pig butchering or some other type of social engineering, scammers know that they can create a sense of urgency. They know they can deliver messages to devices that people are going to engage with and respond to quickly, even when folks know that they shouldn't. And that continues to advance in the age of AI, not necessarily through new scams, but through acceleration of the old scams. Combine that with the broad industry shift ah since late 2024 towards end-to-end encrypted messaging when Apple able to support for RCS, now you have a shift in the controls. that can be put in place or that have been put in place to protect users from this activity because the messages are now are now visible to the defenders in transit. And that's a major shift that's happened over the last couple of years.

Speaker: Okay, so let's break that all down step by step, because I i think the the last point that you mentioned is ah is a really important point. But let's go back to scam messages, um which which will definitely be the main focus of our conversation today. So from the eyes of the telecom industry, walk me through a scam message journey. And what are the points in time where trust is abused? And what are the tools where we can restore the trust? And let's go to let's start with SMS. Okay. SMS is ah is a pretty straightforward one. it's um you know it's an It's an old protocol, right? It's been around for for decades. It's not incredibly sophisticated and it's unencrypted. And so if you think about how... And it's still the most widely used for scams today in terms of like all the protocols right now. um and all ah It's still the number one between SMS and email. Those are the leading to textual communication methods that are abused by criminals. Not saying that they're not shifting, but then...

Speaker: Yeah, 100%. And the thing about SMS is that every mobile device can send and receive it. I think that's the important thing, right? It's it's baked into the to the platform. And so it's the it's the the lowest friction route to get a message in front of somebody. But I think what a lot of folks don't think about is, you know, there are a lot of different ways for an SMS to...

Speaker: originate from a threat actor and end up on on someone's device, right? You have, you know, peer-to-peer, which is SIM-enabled traffic. That's, you know, a device with a SIM card to a device with a SIM card. You've got A to P, which is application to to to person traffic, which would go through a cloud platform, like think like a Twilio, somebody like that. And then you've got a number of flavors in between in terms of how to deliver those messages. But there are different pipes through the network. It's not as simple as, oh, there's this one pipe and we can just stop things. So the traditional controls have been sms firewalls that are employed by the the wireless networks um and they sit in the flow of traffic and they do everything from, you know, volumetric analysis of of messaging across the different numbers, sending them to content analysis and and everything in between. So who owns the SMS gateways?

Speaker: um Typically, like in the United States, for example, a large portion of it is going to be through companies like Proofpoint, who purchased a company called CloudMart a while back, and companies like Aenea, who purchased a company called Adaptive Mobile. Those would be primarily the top ones that are um performing the the filtering today, although there's long tail of others. Yeah, but that's the technology used, but who owns that? Who is buying that technology and kind of managing? Is it the telcos?

Speaker: ah The telcos are contracting with those organizations to provide that capability inside the mobile network. um So it's it's silent to the user, right? The end user doesn't know these companies exist, doesn't know this filtering is happening. And um these organizations have somewhere around the range of 10 milliseconds to make a a ah blocking decision, um which is not terribly much time. And it's pass-fail.

Speaker: Correct.

Speaker: You talked about two things right now in in terms of the filtering. One is the volume. ah So volume of numbers, volume of messages. So if we see too much volume, then maybe that's a signal to block.

Speaker: And the other or a message that repeats too many times that but likely spam or a scam um signal to block. But you also talked about content filtering. Besides the repetition of content, is there another means of ah content filtering at that point in time?

Speaker: Well, sure, since SMS and and um MMS are unencrypted, um you know, there is analysis that can be done on the content of a message. So to your point, it it could be, you know similar content being repeated, or it could just be the nature of the content, you know, fingerprinting certain types of scam content that is intended to look like legitimate messaging but may have certain tells that it's not. um Also doing analysis of the ah URLs in the messages. A lot of times there there will be you know malicious yeah URLs that whether they're shortened or they're um dynamically generated yeah URLs that you know have certain tells that they are malicious or when you interrogate them you might see something about the infrastructure behind them that is malicious. And so these are all ways that these filters can and not analyze this messaging. Within the 10 millisecond timeframe, they're doing that that type of analysis as well? Yeah.

Speaker: And it's it's not a lot you can do within that timeframe, even with the best technology, right? There's a lot they can block. with this is This is why it's it's not as simple as just saying, oh, the wireless carrier should just block this stuff. Why can't they make it stop? um Because there's there's not a lot of time.

Speaker: Exactly. Because my next question is, wait, with all this technology, there's still so many scam messages and SMS. So so what are can we break down the limitations a little more? I think one of the broader limitations is just the time. um There's not enough time to do that level of analysis, especially around the broad range of you know billions of messages that are going out. And so there's the ability to stop you know a good chunk of malicious messaging. But I think the other thing you have to think about is that these firewalls are not just meant to stop phishing and scams. They're meant to stop the broader, sort of more murky challenge of spam, um which is more of a question of consent. And obviously,

Speaker: nobody's consenting to receive malicious messages. So it's ah a subset of it. But um there's a much broader range of abuse messaging or nuisance messaging that's also being filtered. And so it's it's a relatively complex issue to try and tackle within the constraints of messaging. And there are you know requirements that the you know the the wireless networks are delivering communications, right? That's a core function. And so there's only so much they can hold back before they have to you know enable legitimate communications. I think imagine the types of communications that you wouldn't want held back even for protection like emergency services.

Speaker: You know, really, really time critical messages that you you don't want to hold back um even if they might be malicious. And so there is this sort of judgment call that has to be made on what to let through and whatnot within a very limited amount of time.

Speaker: Interesting, because my next comment was going to be, we talk a lot about, you know, faster payments in the in the financial industry. and And I keep hearing again and again from financial institution fraud fighters, can we just slow down the payments? Because we don't have enough time to talk to the customer, to make a decision. Why is why does a payment need to go so fast? um So kind of, if we could do slower communications, but I can see all the reasons why We've reached a standard that maybe this is not possible. Is there any conversation in the telco industry about, wait, maybe it's maybe we give it more than 10 milliseconds to make a decision?

Speaker: I don't think I've been involved in that particular conversation, although I think it's ah it's a valid question. But I also think there's ah a certain expectation of the user that um messages go through seamlessly and that it's a you know it's a perfect process. And I think you know um you know the telecommunications industry is sort of this world of churn, right? where yeah you know, you've got these customers and if they're upset with your network, well, the grass is always greener. I'll switch over to the competitor. And so it's always this ongoing challenge to ensure that you're keeping up with the the next organization in terms of level of service. And i think, you know, speed of delivery, um you know, connectivity, just a seamless engagement is um is really, really important to these organizations being successful. And just like anything else, has to be weighed with security.

Speaker: Yeah. Still, ah you know, customers asks expect the money to move quickly. and And we're talking about delaying that. Not that, again, it's it's being done, but I think there are delays when the risk is high. We want an extra check that that would potentially make sense. But ah it it sounds like a Pandora's box to open right now.

Speaker: I think, you know, when you when you think about financial transfers versus delivering a message, I think the delivery of the messages is the potential start of a malicious engagement. But you don't know. Financial transfer, once the money's moved, it's very hard to to move it back. And I think there are a lot more signals that can come into, you know, whether or not a financial institution authorizes a transfer on both sides of the transfer that don't need to happen within 10 milliseconds. And I don't think the expectation of financial transfer is 10 milliseconds versus messaging. So i i I think it's to some extent is is a little bit apples and oranges. But if you could and institute some friction at the delivery point of the message, um i I think that is one angle to be able to address this. um And I think to some extent, that's the direction that we're going in terms of of you know migrating to end end encrypted messaging and and shifting the the burden of defense off the mobile network itself and onto the device.

Speaker: Yeah, and ah of course, I'm not saying that ah a message being delivered on the but mobile network and a payment transaction are the same. I'm saying that the the constraint of speed is in both cases ah blocking us for or or hurdle putting hurdles in trying to assist the consumer and and and and really support them. um and And just something to think about.

Speaker: Personally, I would wait another 10 milliseconds to get a more more secure message and less spam. but But I understand the current constraints So we talked about SMS a little bit um and the level of filtering that's done and still so many messages are getting through. And I understand part of that is the the time constraint. So we talked about phishing, for example, the ability to go and resolve URL and really understand what I've seen when I look go to different websites and and try to check a message. It takes a few seconds, not a few milliseconds. It takes time to have a serious, um and even then they're wrong many times. You know, deeper analysis is needed in many cases. So definitely the 10 milliseconds, not enough. Then what's next? What ah what else do the telcos try to do to protect their customers today? Well, I think pretty much all of the telcos, at least in the States, do have, you know, mobile security apps that are part of their their brand and their portfolio that they put on devices. um Whether these are apps to support with suppression of malicious robocalls, um whether they include an antivirus component, whether they include a mobile messaging filtering component. And there are controls and and APIs within the mobile operating systems from you know from Apple and Google that do enable some level of message inspection on the device, whether that's encrypted messaging or unencrypted messaging once the the messages hit the device. and ah To go to my earlier point, right, a 98% open rate within 90 seconds doesn't mean that that 98% opens it within the first second. So I think there is time once the the message hits the device to do some further inspection. And there are, whether they're directly carrier branded or carrier partner apps or third party apps that can be put on the devices to do that deeper inspection. Like Scam Ranger? Like Scam Ranger. That's a fantastic example. And there there um obviously are others as well. um They can do a little bit more of that analysis once the message or the call hits the device. So I think that that there's definitely more to be done there. and And to a large extent, that's where we're going in terms of the only controls that'll be left once everything is end-to-end encrypted.

Speaker: Yeah, and so that's really, i think that we covered two points here. One, the notion of, okay, here's what we can do on the network level, and we have very limited time, and we can only look at traffic or content that is unencrypted. So once we shift to more and more encrypted traffic, our ability to do something on the network, obviously, is deteriorating. And then once it's on device, then we have a little more time and we can put a lot a little more controls. And I know that both Apple and Google are are doing something, too. They're not just saying, OK, here are APIs. They're actually doing some filtering themselves. um But you also raised a point earlier of the so let's let's talk about the encrypted communications and where the challenges are for telcos once the things become encrypted and then where the responsibility lies. Sure. So there was a ah big shift in um September of 2024 when Apple finally enabled support for RCS messaging um on iPhones. And and basically, i don't want to say overnight, but quite quickly, a large chunk of traffic just went dark for the wireless networks because it was... And i I'll stop you just, sorry, for another second, because again, you're you're living and breathing this, but let's go. i think we're familiar with the term RCS, but prior to Apple enabling this on their networks, Android had supported RCS, originated RCS and supported RCS for a long time before prior to that. So the shift in 2024 was that Apple now enabled that. So first of all, what is RCS? And then maybe continue the point about what happened for the top. Sure. So that's a good point. let Let's get in our time machine and go back maybe 10 years. So RCS stands for Rich Communication Services. It is a mobile messaging standard that um was set up by the GSMA and has been around for over a decade in terms of a standard that's been defined. um Ultimately, it but it was designed to be sort of

Speaker: the replacement for SMS. And and the the objective ah was to bring all these advanced features that we had come to um become used to from a lot of the over the top services like WhatsApp, like iMessage, etc.

Speaker: In you know everything from you know high definition media to you know typing indicators to read receipts, just there's there's a whole swath of advanced features that are baked into it. And the idea is that it's just the standard, right? That it's built into the the basic level of messaging in every new device. It's taken a very long time to get off the ground. There were various initiatives to try and put it in place with the the different wireless wireless network collaborating with each other to try and launch their own versions. There were a lot of bespoke deployments around the world. But ultimately, Google bought a company called Jive Mobile, with the technology to deliver RCS and basically said that they were going to ah run with it. And by, I think it was around 2021, the majority of of mobile network operators um and a lot of markets had done deals with Google to run the backbone for RCS. So basically became native to Android, which is really one of the biggest steps to to to getting it out there as as a primary standard. Google, as I'm sure we've seen in the press over the last few years, ah publicly put a lot of pressure on Apple to enable support for it. They finally released that support in ah in September of 2024. And what that did was it meant that all of a sudden, all these messages between iPhones and Android that were previously just regular SMS, all of a sudden switched to RCS. And most users didn't notice the difference, right? It was still green bubbles and blue bubbles. um But the underlying technology was different because it went over the top, meaning it didn't go over the the carrier network. It went over the data network um across Apple and Google's pipes. What that means is the wireless networks can't see this messaging. They can't see the content. They can't even really see what is being sent.

Speaker: So the only role that the mobile network operator plays practically in this process is tying the SIM cards to the RCS identity. And that is kind of the the area where the mobile network does have ah a responsibility to act when a number is identified as sending malicious RCS messaging. They have the ability to deactivate that SIM card, which will shut down the RCS messaging from that number.

Speaker: So after the fact, after something is flagged for being malicious, then they can act, but they don't know. They can also act up front if they know that, you know, just to the conversation last week, if that number is not to be supposed to be sending communications or that number has a problem, right? But they don't have any visibility into the message, so they can only act in retrospect, shut down that communication for that number.

Speaker: Correct. They can't even use volumetric controls because they're not seeing the messaging going out. So the only way that they will know is if people are complaining to them that there's messaging coming from this number. um So they do have the ability to act, but they need third-party data sources to provide them the intelligence that this sim is being abused to take action on it. So there's a control shift here. That's ah very interesting. First of all, that that step that Google took is fascinating. um All the telcos trying to agree on the protocol and exactly how it will look. And then Google's like, just use this. And do they own, do they control something within RCS now that they kind of set the standard or not really anymore? Well, they control the technical backend to it. So they're they're literally running the infrastructure and the servers that enable the delivery of RCS. Obviously, they need to partner with Apple for delivery from Apple devices. ah But they they they run the Rails um on behalf of the the wireless industry. Now, it does require integrations with all the different M&Os, and there's a lot of technical complexity to delivering that. But otherwise, it it's running over their network. Mobile mobile network operators, yeah. MNOs, mobile network operators.

Speaker: Yeah, industry acronyms are always the best.

Speaker: Before we get back to the conversation, I wanted to share something we believe deeply at Rangers AI. The future of fraud prevention isn't just about detecting suspicious transactions. It's about giving people the confidence to make safer decisions before money moves.

Speaker: Every day, customers receive texts, emails, phone calls, and messages that look legitimate. By the time the transaction reaches the bank, the customer may already have been manipulated.

Speaker: And that's why we built ScamRanger. ScamRanger helps people evaluate digital communications in real time, understand the warning signs of scams, and know what to do next. It empowers customers to make important decisions while giving financial institutions another layer of insight and protection. Because the strongest defense against scams isn't just better technology. It's building scam resilience, one decision at a time.

Speaker: Now, let's get back into the conversation.

Speaker: So let's talk about control then. So RCS is encrypted, but they're on device. We talked about off on network. We have much less access on network. So actually, I had a question before. Why was Apple so hesitant to implement RCS? Is it because they had their iMessage protocol and then they wanted to keep using that, which they're still using Apple to Apple? But I'm just curious if you have any insight into that. I think there's a lot of speculation around that. um And I think there's a lot of folks that have a vested interest in it and sort of one narrative or the other. the i think the official Apple position was that RCS at that point in time was was not secure enough. And then encryption at that point in time was not supported by the universal profile under GSMA. And so what Google had done is Google isn't necessarily using the the the universal profile from GSMA. They're sort of using their own version of it. And Apple wanted to stick with the industry standard, which, you know, from their position was not up to the security standards that they held. And so until the industry standard got to the point where they wanted it to be, they weren't going to play ball with it. Now, we can all speculate on whether or not that's true or there's other, you know, commercial interest at play. But that was effectively the dialogue that was going on for a number of years. Okay, so hopefully there was a change in the security protocol to bring it up to what ah to the standard that they're striving for, which is hopefully better for us consumers.

Speaker: So end-to-end, on the network encrypted, on-device unencrypted. So what does that mean in terms of who is now responsible to protect consumers from scams when it comes to messaging? Well, I think responsibility is ah is a complicated topic, right? I think who is responsible? can Who can protect consumers? But I think it's an important point, the responsibility versus who can, because I think responsibility is it depends on the regulatory environment and in every market that these platforms operate, and that

Speaker: differs across the globe. and And you see this, it's different in the US versus Singapore versus Australia versus the UK versus in certain country here. So responsibility could be a bit of a loaded term. And I'm sure various parties would have different opinions in terms of who can take steps to protect. Certainly, the the OS, OEMs, Apple and Google can take steps and do take steps to protect, right? They both have their on-device AI controls that are scanning messages after they're decrypted on device and taking various steps to move things into a ah spam inbox and try and keep bad messages um away from users' eyeballs, right? So they're not engaging with them. And they work okay. But ah clearly, the the fraud numbers you know speak for themselves in terms of messages are still getting through, people are still engaging with them, and you know you can't build a perfect mousetrap.

Speaker: I don't think it is necessarily fair to say Google and Apple should be 100% directly responsible for those controls. I think it's it's admirable they put some in, but ultimately, neither one of them are security companies by role, right? And so what we do need is is um other tools like ScamRanger, for example, that are focused on security and will compete with other platforms on security, leveraging the sandbox on those devices to be able to protect users better. But I think the The interesting shift here is that in order for a user to have one of those applications on those devices, especially on iOS, which doesn't allow preloads, they have to make a decision. Oh, I need an app to protect me. I need to go find the best one. I need to download it.

Speaker: I need to put it on the device and make sure it's working. Your average consumer isn't doing that. So whereas, you know, previously the wireless networks would, you know have these controls installed the network and the user doesn't even know they exist. Now the user has to actually make ah an affirmative decision. i'm not you know happy with the security of my device and I need to install something or someone's got to decide I need to put this on my parents phone or my grandparents phone to protect them. And so we're kind of almost back to the old days of making sure you have antivirus on your laptop. So it's it's a little bit it's a little bit different.

Speaker: And the different mechanisms for delivering messaging all have different types of controls that can be put in place. So you know for RCS, it's over the top, except that it is tied to a SIM card. So you can you can deactivate that SIM and the messaging stops.

Speaker: One of the common misconceptions about iMessages is that you can send an iMessage from your phone number. Well, you can use your phone number as an identifier, right? But it's not actually coming from your phone number to another phone number or a SIM to a SIM. It's going from an Apple account to an Apple account. And you can actually register an Apple account without a phone number at all.

Speaker: um which is why you see certain iMessages look like they're coming from an email address, and those are sometimes mistaken as email to SMS, but really it's just an iMessage. um So the ecosystem for defenders is becoming more more fragmented, and so that is in and of a itself and a new challenge. Right. And so I think just to your point earlier, on one hand, Apple and Google have or or the the ability to protect has shifted to Apple and Google. But to your point, they are not security companies and good good for them that they did put some controls in, but they are doing an OK job. I agree with you. And so opening up the ability for cybersecurity companies to protect consumers is definitely something. and And it's not just Apple and Google. i think you talk about it. It's other messaging platforms that consumers are using that are not cybersecurity companies. But if we want to protect the user holistically, having the ability to opt in and agree to the filtering, but also do it in a privacy-preserving way with with deep controls. That will provide full protection. And then that point about, as a consumer, I have to opt in, which is 100% a concern because I don't know that consumer cybersecurity is very, very successful unless there's a good reason for a consumer to do it. One, they were scammed before. Two, for a loved one or someone they care about. Three, there's a really good incentive from someone, either their telco

Speaker: which is not big on incentives to consumers, are more like charging for that. Or a financial institution or an organization that supports them to drive them to actually protect themselves. it's It's probably not going to be um unless there's something that really happened originating from consumers on a mass level. That's correct. So I think when when we talked earlier, my big aha moment was really that shift to Apple and Google owning all this communication traffic that prior was centered more around the telcos and the telco industry. So in the past, globally, we're talking about

Speaker: many companies who share ownership of of this traffic. And now it's two companies that have visibility into this traffic. So their responsibility to provide the means for for protecting consumers is has grown significantly into this industry. So how are they doing so far in your mind, from your point of view?

Speaker: um I think that they could be doing more. I think there could be a greater collaboration with the the wider security industry in terms of establishing ah more robust ah APIs and permissions into the device to be able to deliver more advanced protection. And I think there could be more collaboration in terms of data sharing. ah So if you if you think about some of the other data that you know Apple and Google collect and a subset that filters down to the the wireless networks, you know if you if you go into your messaging client on your Android device or your Apple device, you have the ability to hit ah a button that says report as junk, report as spam. And there are millions and millions and millions and millions of messages that are reported as spam to Google and Apple. And um Spam is a loaded term. I think everybody has a different idea of what they view personally as spam. um A lot of folks just think it's, oh, anything I don't like is is spam. But if I don't want it, then I report it as junk. And so within all that messaging that gets reported directly off the device, back to Google and Apple and ultimately a subset to the M&O's, you know, there's a ton of ah messages that are just... you know, your regular, you have a bill due message or, you know, a message from someone's, you know, mother-in-law that they didn't want or something that that is not actually malicious or spam. But when you when you dig through that data and you you kind of clean up all the noise, just like any other abuse box, there's a ton of intelligence about malicious messaging, where the malicious messages are originating, what types of URLs in them, what are the callback numbers people are being asked to engage with. What are the, you know, the social engineering type conversations that might occur over multiple messages that in individual thread you may not be able to detect, but when you put the messages together, all of a sudden you're, you could see, aha, this is ah this is a scam conversation that's about to go into a, you know, a crypto scam or or something similar. So there's a lot of intelligence that the very small amount of companies have that is not being shared. And if you think about what's in that intelligence that can be leveraged by the broader industry to protect users, you think about um even something as simple as number intelligence. you know These numbers are the numbers that are sending malicious messages, and these are the numbers that are receiving them. Well, imagine what a bank could do with that data.

Speaker: Imagine if a bank knew the the mess the the um the numbers that were in the hands of scammers and they could block list those numbers from being registered as primary communication numbers or numbers that would receive a 2FA token um to to access a bank account or authorize a wire transfer.

Speaker: You talk about putting friction into the flow of money, on being able to use number intelligence to be able to say, you know, the context of this number says its this this particular transfer is higher risk because of this change on this account recently. Or on the flip side, knowing that this number, which is a customer identifier, has been receiving smishing messages within the last 24 hours, they're at higher risk for an account takeover.

Speaker: um They might be at higher risk for a s SIM swap, but we may be sending it, you know, sending a 2FA code to to the scammer, actually. So just between knowing the the the A numbers and the B numbers, meaning the originating numbers and the recipient numbers within the context of how they've been recently interacted with, it's a huge amount of control that could be put in place to protect those users. But right now that data is not flowing to those parties for that purpose. And that's a challenge.

Speaker: That's a big opportunity and and definitely something that we we should raise and elevate as a point of conversation in the industry. um Also, I will say they made, at least on Apple, they made reporting very, very hard in the last few operating system versions. It used to be like click to report. And now it's have to click on the message, go into more, scroll down. It's not so easy anymore to report a message. I'm wondering why they made that change.

Speaker: I suspect it's because people were overreporting accidentally. So with the the Apple and Google reporting functionality went into place and the the network operators started receiving some of that data, it was just massively, massively larger than the amount of data that they had been able to collect through their own bespoke reporting mechanisms previously. So historically, ah there was a short code called 7726 that um Most people have never heard of, but it spells spam on an old T9 keyboard, right? Which tells you how old that is. um But it was all that all we had in those days. And if you were to forward a message to 7726, you know, that would send a message that you were reporting as spam to your carrier. And you would get a follow-up message in a lot of cases that would say something to the effect of, thank you for reporting. Please tell us who sent you this message. <unk> The intent was, well, let us know who the scammer number is or what the scammer number is. And unfortunately, ah most folks didn't actually follow up. There was just a lot of breakage. I think about 20% of people actually responded at that point. And the majority of them would respond 7726 because they misunderstood the question. I thought it was some kind of confirmation step. And so you wouldn't you would see, oh here's the content of scams going out, but you wouldn't know where they were coming from.

Speaker: Once the the Apple and Google reporting went into place, we had all the metadata. You know, you you would get the sender number, the date, time stamp of when the message was received, the full message content, the recipient number, some other metadata, great amount of data. But it was also so easy to report that there was overreporting. It was also easy if you were going through your messaging inbox and you were trying to clean it up and you've multi-selected 100 messages and hit delete, there'd be a pop-up that said, do you want to delete or do you want to delete and report spam?

Speaker: And so people would fat finger that and they'd report 100 messages as spam. And so there was just a huge amount of data flowing in, but a huge amount of noise. um And so I think that's likely why there's been a little bit more friction put into the process.

Speaker: Okay, interesting. I i just ah don't know that too many people will be able to report right now unless they've done it before or actually search for it. But um I do hope that that data is being used. And I think the visibility into that data is critical to you know, from an ecosystem, we always ask kind of about data sharing, what could be shared with what, and we understand there are ah privacy issues and regulatory issues, but this data about malicious actors that Google and Apple now have. And the network, sorry, the telcos, do they get this data? Because I'm constantly being asked, where what happens when we report a message?

Speaker: They get a subset of the data that is what Google and Apple have ever agreed to provide them. Google and Apple are the only ones that have the the superset of the data. And i I do want to be clear, the data is being used. Historically, it was used by the wireless networks to measure the effectiveness of their their SMS controls. It would be used to feed back into the SMS firewalls to build a better mousetrap and to enhance the the filtering rules. Google and Apple are undoubtedly using it to help train their AI models to build better controls on the device. So it is making it to a a a small number of organizations in the defender ecosystem, but the intelligence is not making it to where it's most actionable, which is the financial services community. And and that's where I think we need to find a way to get beyond some of the the privacy objections, um because more often than not, I see privacy, not just in this case, but in in broader cases, being used as a reason to not defend because of the risk of falling afoul of a privacy regulation that could result in some kind of finer legal action And I find it very odd that privacy regulation and consumer protection are at odds with each other because they should be two sides of the same coin. But right now they're not. Right. So what's next? What's next for you and what's next for the industry? And what's next with RCS or yeah other there emerging trends in this industry that you think are important to look at, to look out for? Well, I mean, certainly I think um a major part of what's next on both sides of the fence is AI. And in fact, it's not next. it's It's already here. And I think we've seen it in terms of some of the the tools that defenders are building to be able to process large amounts of data faster.

Speaker: um i think speed is still going to be incredibly important in terms of defense. Unfortunately, the threat actors are using AI as well. And they're using it more effectively because they don't have privacy controls to care about. They don't have regulations to care about or laws to care about because they just ignore them. They're criminals. And so I think we do have a disadvantage there.

Speaker: I think there's a lot of talk about you know ai in terms of of new types of fraud. And to some extent, I think that is true. But I also think that it's just accelerating the old types of scams. When it comes down to it, the majority of fraud is it comes down to social engineering um and various forms of hacking the human. And AI is just making it easier to scale with fewer resources. um You know, when you think about the fact that over 60% of phishing is now phishing as a service. It's now just a SaaS platform that anybody with a couple of bucks or a stolen credit card spending somebody else's money can sign up for and deploy one of 100 pre-canned scam pages with built-in encrypted messaging services and geo-broken AI models to build the content. I mean, it's just, it's out of the box. It's paint by numbers at this point. It's not even pre-canned. You can actually select a website and copy it very quickly with AI. And there are tools that they're pre, you know, you can buy tools to do that. But I don't, I think it's that you don't even need that at this point. You can just use AI to do that. And that's pretty scary. But you're right. I think the common denominator is human behavior, right? Once criminals are focused on social engineering humans, then It's not about AI to create really sophisticated attacks. It's about AI to be custom tailoring the messaging to this individual personalization as supercharged, not also value, but the ability to pivot in that moment is something that AI probably does much better than us.

Speaker: I think so, and I think that's part of the challenge. But I think if you look at it on the flip side, there's an opportunity. mean, if you think about all of the access that people are giving to AI to make their lives easier at their own expense for privacy. Right.

Speaker: You think about that in terms of security, you could you could do the same thing. You could give access to all the data from your apps and and all this other stuff, but to a security application to be able to leverage that data for a security function. And you'd be able to do a lot more with that if you were able to deploy AI in that way. But I don't see that happening just yet. And I don't see the access to that happening just yet in a way that could be meaningful in the way that the threat actor is doing it. But that does also kind of open up Pandora's box at that point in terms of, well, how is that going to be abused as soon as that's opened up? So it's definitely a complicated question. I mean, I do think we need we need a bit more advanced regulation around who is responsible for some of these controls. And I do think we probably need some regulatory guardrails to steer um industry in the direction of ah not only ah taking more responsibility, but also building some safe harbor for organizations that are afraid of privacy regulations. If we could build some rails for safe harbor that are a little bit more robust to enable defenders to not be able to throw up those roadblocks, I think that could go a long way as well towards innovation. um So, so many important points raised today with you know the ownership of the the data now with Apple and Google, but them opening it up, ah the the data that they have and need to share. i feel like it's all coming back to them. So I really hope there are good participants in the ecosystem. I know that there is a lot of data sharing going on, but I don't know to what extent and what specific you know pieces of information. I hope they'll be listening to this ah episode and and think about those things as well.

Speaker: I wanted to thank you so much for your time today, ian And this has been so insightful to me and and I'm sure the listeners who are not necessarily typically from the telco industry. And good luck with your new endeavors and hope to have you on the podcast very soon again.

Speaker

Speaker

Speaker

Speaker

Speaker

Speaker

Speaker

Speaker

Speaker

Speaker

Speaker

Speaker

Speaker

Speaker

Speaker

Recommended