Your MVNO Is a Fraud Target. Most Operators Find Out the Hard Way.
Subscription fraud costs MVNOs $500–$1,200 per fraudulent account. SIM swap attacks are being redirected toward less protected subscribers. Here is what the threat surface looks like and what a real fraud prevention posture requires.
Let's start with a number that should get your attention. Subscription fraud accounts for 30 to 40% of fraud losses at many MVNOs, with each fraudulent account costing $500 to $1,200 when you factor in device subsidies, SIM costs, activation expenses, unpaid service usage, failed collection efforts, and the staff time spent chasing accounts that were never going to pay. At any meaningful subscriber volume, that is not a rounding error on your P&L, it is a line item that can quietly drain margin for quarters before anyone names it.
Subscription fraud is only one piece of the exposure. SIM swap fraud, synthetic identity fraud, card testing, and payment fraud at the activation layer each represent additional threat surfaces that most MVNOs are significantly underestimating, and the reason is usually not carelessness. Fraud prevention simply was not in the original business plan, and by the time the gaps become visible in the financials, the losses have already been compounding for months.
I have worked with enough MVNOs to know that fraud is one of those topics everyone acknowledges and few actually operationalize. So let me walk through what you are actually dealing with, why MVNOs are disproportionately exposed compared to the MNOs they ride on, and what a functioning fraud prevention posture actually looks like in practice.
Why MVNOs Are a Preferred Target
The short answer is that MVNOs combine three things fraudsters find very attractive: digital-first activation, thin or inconsistent identity verification, and prepaid economics that limit the immediate consequence of a fraudulent account.
An MNO with a retail footprint has a physical layer in the fraud chain. An in-store activation requires a human interaction, often a photo ID, and sometimes a biometric check. That friction does not eliminate fraud, but it raises the cost of executing it. Most MVNOs have eliminated that friction deliberately because it also functions as a conversion barrier, and a frictionless digital activation that converts more legitimate customers also converts more fraudulent ones. The economics of fraud improve significantly when the fraudster never has to show their face.
Prepaid economics compound the problem. A fraudulent postpaid account requires the fraudster to survive a credit check and pass identity verification before they can access subsidized devices or accumulate unpaid usage. A fraudulent prepaid activation at many MVNOs requires little more than a stolen or synthetic identity, and in some cases the barrier is even lower than that. The barrier was lowered by design to reduce friction for legitimate customers, and fraudsters understand the resulting exposure better than most operators do.
The third factor is network data visibility. An MNO can see network-level signals that are invisible to the MVNO, including device behavior across the network, historical account patterns tied to device identifiers, and usage anomalies that tend to precede fraud events. The MVNO sees what the BSS sees, which is the commercial transaction layer. The signals that would enable earlier fraud detection are sitting in systems the MVNO cannot access, and that structural gap is worth understanding before building a fraud prevention program.
Subscription Fraud: The One That Bleeds You Slowly
Subscription fraud is what happens when someone activates service using a stolen or synthetic identity with no intention of ever paying. In a prepaid context that can sound almost trivial, because how much damage can a fraudster do on a $35 plan? The answer is that the immediate service loss is relatively small, but the total operational cost is not.
The fraudster receives a SIM that can be used for a range of downstream purposes, including intercepting SMS-based two-factor authentication codes to compromise other accounts, reselling the activated line, or deploying it as part of a larger fraud infrastructure. The MVNO absorbs the SIM cost, the activation cost, any device subsidy involved, the wholesale network cost for usage before termination, and then the collection effort cost for an account that will never pay. When those costs are aggregated, the $500 to $1,200 per fraudulent account figure from industry data becomes very credible.
Volume is what makes subscription fraud genuinely dangerous. A coordinated fraud operation does not probe your activation portal with a single account. It hits the portal with hundreds of attempts over a short window using an inventory of stolen or synthetic identities. If your fraud detection is manual or built on rules with obvious bypass patterns, a well-resourced fraud ring can activate a significant number of accounts before your team identifies the anomaly in the following week's reporting.
Synthetic identity fraud is the variant that is hardest to catch. A synthetic identity is a constructed identity that combines real elements, often a legitimate Social Security number belonging to someone with a thin credit file, with fabricated name, address, and contact information. These identities do not match known fraud signals because they do not belong to a known fraud victim. They pass standard identity verification checks because portions of the identity are genuine. Synthetic account fraud attempts grew 153% from late 2023 to early 2024 across financial services, and telecom is rated as the second most impacted sector after banking. The MVNOs with the strongest fraud controls are catching synthetic identities through behavioral signals at activation, looking at device fingerprint, network connection, browser or application characteristics, and the velocity of the activation attempt, rather than relying on identity document checks alone.
SIM Swap Fraud: Your Subscriber Is the Target
SIM swap fraud is different from subscription fraud because the MVNO itself is not the primary target. The subscriber is. The fraudster's objective is to hijack a subscriber's phone number by convincing your customer care team or self-service portal to transfer the number to a new SIM. Once they control the number, they use it to intercept SMS-based two-factor authentication codes and take over the subscriber's bank accounts, cryptocurrency wallets, or other high-value accounts. The subscriber's phone goes silent, the downstream accounts get drained, and the MVNO finds out about it through a complaint call or a social media post.
I want to spend a moment on the US data because the numbers deserve some explanation before you accept them at face value, and because the three-year trend tells a more nuanced story than a single headline number does.
The FBI's Internet Crime Complaint Center recorded 971 SIM swap complaints in 2025 with $17.4 million in reported losses. In 2024, that was 982 complaints and $26 million in losses. In 2023, it was 1,075 complaints and $48.8 million. So complaints are essentially flat over three years while reported losses have dropped by more than 60%. If you look at that trend and conclude that SIM swap fraud is becoming less of a problem, let's dig deeped into the analysis of what it means.
The math behind the averages tells you part of the story. In 2023, the average reported loss per SIM swap complaint was roughly $45,400. In 2024, it was $26,400. In 2025, it was approximately $17,900. That trajectory reflects something real: the highest-value targets have gotten harder to hit. Cryptocurrency platforms and financial institutions have gotten meaningfully better at detecting SIM swap as a precursor event and freezing accounts before the drain completes. The GSMA's SIM Swap API, which lets banks query carriers in real time before approving high-value transactions, is being adopted. The $500,000 crypto wallet drain that was routine in 2021 and 2022 is harder to execute today because the receiving end of the attack has better defenses.
But complaint volume being flat is the signal most people miss. If the fraud were actually getting harder to execute, you would expect both the complaint count and the losses to decline together. The complaints have barely moved, which tells you the attack volume is holding steady while the fraudsters are landing smaller payoffs per successful attack. They are not being deterred, they are being redirected toward victims with fewer protective layers. And for an MVNO whose subscriber base skews toward underbanked and immigrant communities, that redirection is not reassuring news. The fraudsters who can no longer drain a $400,000 cryptocurrency wallet are running the same social engineering attack against someone's $2,000 savings account, and the MVNO's customer care agent is often the weakest point in the chain.
The complaint numbers also substantially understate the actual incident volume, for two structural reasons. The first is that SIM swap functions as an access mechanism rather than the final fraud event. The victim whose SIM was swapped and whose bank account was then looted may file a complaint about account takeover or identity theft, not about the phone number hijacking that made it possible. The mechanism goes unreported because the victim experienced the consequence, not the cause. The second is that most victims resolve through their bank or carrier dispute process without ever filing a federal complaint. The IC3 data captures the high-value targeted attacks where victims took the additional step of reporting to the FBI. It does not capture the broader population of incidents that resolved through bank chargebacks and carrier adjustments.
MVNOs are particularly exposed in this area because of customer care depth. A well-resourced MNO has multiple authentication layers, strict SIM change protocols, mandatory waiting periods, and trained fraud specialists who handle escalated cases. Many MVNOs process SIM swap requests through general customer care agents trained primarily on service delivery rather than fraud prevention. A social engineering attack that would fail at a major carrier because of protocol depth can succeed at an MVNO because the agent has been trained to be helpful and the procedural gaps are real.
The FCC adopted rules in 2023 requiring carriers to implement enhanced authentication for SIM swaps and number port-outs, including immediate customer notification. The original compliance deadline of July 2024 was waived after carriers requested additional time for system upgrades and staff training, and as of this writing there is no new enforcement date. The practical implication is that the regulatory floor for SIM swap prevention is not yet enforced, and operators below that floor remain exposed, particularly as the fraud community continues redirecting its efforts toward less protected subscriber populations.
Payment Fraud and Card Testing: The Activation Layer
The MVNO activation flow is also an attractive surface for payment fraud, specifically a technique called card testing. A fraudster holding a large inventory of stolen card numbers needs to identify which ones are still active and have not been blocked by the issuer. A small transaction is the standard test, and a $35 prepaid activation is a near-perfect one. If the charge clears, the card is live and worth deploying for larger purchases elsewhere.
The MVNO absorbs the chargeback when the legitimate cardholder disputes the transaction, along with the chargeback fee from the payment processor and the cost of the SIM that was activated in the process. The fraud operation validated a card, your customer care team handled the dispute, your billing operations team processed the chargeback, and your payment processor noted an uptick in your chargeback rate.
That last point carries consequences that go beyond the individual transaction. Payment processors monitor chargeback rates closely, and a rate above approximately 1% triggers responses ranging from higher processing fees to account termination. An MVNO that becomes a popular card testing target can find its payment processor relationship at risk at precisely the moment that relationship is most critical to operations.
What a Functioning Fraud Prevention Posture Looks Like
Fraud prevention for an MVNO is not a one-time vendor purchase or a policy document that lives in a shared drive. It is an operational function that requires ongoing attention, tuning, and investment. The operators who treat it as a checkbox tend to find the losses in a quarterly review without being able to explain where they came from.
A functioning posture has three layers, and in my experience most MVNOs are missing at least two of them.
The first layer is identity verification at activation. This means going beyond standard document checks and incorporating device intelligence, behavioral signals, and velocity monitoring into the activation flow. Device intelligence looks at whether a device fingerprint has been associated with previous fraud attempts, whether the IP address is a known proxy or VPN, and whether the device and identity signals are consistent with each other. Velocity monitoring flags when the same device, IP, or identity element appears in multiple activation attempts within a short window. These signals are what catch fraud rings operating at scale, because a fraud ring's identity inventory is large but its device and network infrastructure often is not.
The second layer is transaction monitoring for SIM swap and account change requests. Every SIM swap request and every port-out request should trigger an immediate notification to the subscriber through a channel other than the number being changed, which would be email or a push notification through the mobile application. Before executing a SIM change, the carrier should require multi-factor verification that does not rely on the number being swapped. Mandatory waiting periods of 24 to 48 hours before SIM changes take effect stop a meaningful fraction of social engineering attempts, because the fraudster needs the number immediately and a waiting period breaks the attack sequence.
The third layer is payment fraud monitoring at the activation layer. This means real-time scoring of payment transactions for card testing patterns, which include small transaction amounts, high velocity from a single device or IP address, and card BINs that appear across multiple activation attempts in a short window. Chargebacks should be tracked by activation channel, device type, and geographic pattern to identify concentrations of card testing activity. If a specific dealer location or digital channel is generating a disproportionate share of chargebacks, that pattern is a signal worth investigating before it becomes a pattern worth explaining to the board.
The Regulatory Exposure Most Operators Overlook
Fraud prevention is also a regulatory compliance issue, and this is the dimension that tends to catch operators off guard when it surfaces. Weak KYC processes that allow fraudulent accounts to activate on your network create exposure under FCC rules, state consumer protection regulations, and the MVNO agreement with the underlying carrier.
Most MVNO agreements include representations about KYC and fraud prevention practices. If fraudulent accounts on your network are used to facilitate illegal activity, the carrier's compliance team will be asking questions, and the absence of a fraud prevention program is not an answer that protects the MVNO agreement. The carriers have their own regulatory exposure from traffic that runs on their network, and they take the pass-through compliance obligations seriously.
The FCC's SIM swap rules, when they are eventually enforced, will impose specific requirements for authentication and customer notification that will require changes to systems and processes. Operators who have already built toward those requirements will find compliance relatively straightforward. Operators who have not will be retrofitting controls under regulatory pressure, which is consistently the most expensive way to get there.
What This Actually Costs
Industry data puts the per-fraudulent-account cost at $500 to $1,200 when all losses are compounded. At a 100,000-subscriber MVNO with a fraud rate of just 2%, that represents 2,000 fraudulent accounts. At the low end of that cost range, the annual fraud loss is $1 million. At the high end, it is $2.4 million.
A 2% fraud rate is not an elevated fraud rate for an MVNO operating without active fraud controls. Operators without controls routinely see rates significantly higher. The 30 to 40% share of total fraud losses attributable to subscription fraud alone suggests this is a material financial exposure that most operators are not explicitly budgeting for, because it does not show up as a fraud line item in the P&L. It shows up as unexplained margin erosion, higher churn, elevated chargebacks, and operational costs in billing and care that seem disproportionate to the subscriber base.
Fraud does not announce itself. It appears in the financials as something that looks like an operational problem rather than a fraud problem, and by the time the root cause is identified, the losses are already significant and the patterns are embedded in the activation and billing systems.
The MVNOs that catch it early have fraud controls built into the activation layer, transaction monitoring running in real time, and someone accountable for the fraud rate as a measurable KPI. The ones that catch it late are usually trying to explain to a board why margins are below model, without a clear answer for where the gap went.