This article is a free excerpt from inCOMPLIANCE, ICA's bi-monthly, member exclusive magazine. To gain access to more articles like this, sign in to the Learning Hub or become a member of ICA.
With mobile messaging fraud rising, firms must recognise that no single control is sufficient to avoid regulatory censure, writes Stefano Nicoletti
No one in possession of a mobile phone will be remotely surprised to discover that fraud via mobile messaging is growing. Worryingly, it is evolving faster than traditional regulatory responses can contain.
The rapid evolution of AI is expected to accelerate the problem. AI is already enabling highly convincing robocalls where the voice on the other end is indistinguishable from that of a real person, as well as the emergence of industrialised ‘fraud-as-a-service’ ecosystems, where criminal groups combine automation, generative AI and crypto-based payment rails to run large-scale scam campaigns.
The fraud landscape, as a result, is becoming significantly more complex, more scalable and harder to detect. Estimates suggest that global fraud losses are already in the region of $40 billion annually, underlining the magnitude of the challenge and reinforcing the need for coordinated, adaptive and multi-layered control frameworks.
Estimates suggest that global fraud losses are already in the region of $40 billion annually.
Telecoms fraud: A moving target
Before compliance professionals can push back against the threat, we need to acknowledge three realities.
First, we need to recognise the scale of the problem. Consumer exposure to smishing (SMS phishing, i.e. phishing attempts made through texts) continues to rise, with more than 40% of users reporting fraudulent text message experiences in recent years.
Second, we need to acknowledge that telecom regulatory frameworks are converging around identity, traceability and proactive prevention, placing explicit obligations across the messaging value chain.
Third, perhaps most importantly of all, we need to understand that no single control is sufficient – effective mitigation requires coordinated, layered measures combining regulation, technical controls and industry driven action.
Source: MEF Data (2026)
Fraudsters operate within a dynamic system and adapt quickly to new controls. A useful analogy is water flowing through a stream: when barriers are introduced, the flow does not stop but finds alternative paths.
In the same way, fraudsters shift across channels, geographies and vulnerabilities, exploiting gaps between national regulatory regimes and inconsistencies in implementation. Measures that are effective in one market can simply displace fraudulent activity elsewhere.
For compliance, this has two implications:
- there is no single silver bullet capable of eliminating fraud, and
- controls must operate simultaneously, dynamically and in coordination.
Static or one-off interventions are insufficient. Effective frameworks must be iterative and responsive, with continuous monitoring and adjustment as threats evolve.
Evidence from the Mobile Ecosystem Forum’s (MEF’s) global consumer survey highlights the scale of the challenge. The proportion of consumers reporting exposure to fraudulent text messages has increased significantly – from approximately 23% in 2020 to over 40% by 2025, with only limited stabilisation thereafter.
In several markets, exposure levels approach or exceed around 50% of consumers, confirming that smishing is now a mainstream and persistent threat rather than a niche risk.
This, for compliance teams, is a critical signal: even where controls are improving, fraud exposure continues to grow, reflecting the adaptability and scalability of fraudulent activity.
Expanding regulatory expectations
It is worth examining in more detail three key areas – mobile network operators, aggregators and messaging providers, and enterprises and brand senders – and how the growth in regulatory expectations affects each in different ways.
Regulators increasingly require mobile network operators to:
- implement network-level filtering and blocking
- enforce sender identity validation controls
- provide traceability and auditability of traffic, and
- support real-time cooperation with regulators and law enforcement.
In the UK, further regulatory clarity for network operators is expected shortly. Ofcom is due to publish the outcomes of its consultation on measures to combat mobile messaging scams later this year, building on broader obligations under the Online Safety Act and ongoing government focus through the Joint Fraud Taskforce. The consultation is expected to address areas such as enhanced sender identification, network-level controls, and strengthened expectations around KYC and know-your-traffic (KYT) processes.
Analysing these developments, compliance teams can expect a continued shift towards more prescriptive and enforceable requirements, as well as increased regulatory scrutiny on how effectively organisations prevent fraudulent messaging from reaching consumers.
The UK government has also intensified its strategic focus on fraud linked to telecommunications channels. It has allocated some £200 million to tackle fraud originating from telecom vectors – now recognised as the most commonly reported crime in the UK. It is a commitment underlined by the publication of the UK Fraud Strategy 2026 to 2029, which sets expectations for closer collaboration between government and industry in preventing fraud at source. In parallel, plans are underway to establish a dedicated fraud observatory, aimed at improving intelligence sharing and promoting more systematic use of cross-sector data.
For aggregators and messaging providers, meanwhile, intermediaries are now subject to heightened scrutiny, particularly for cross-border traffic. This includes robust KYC processes, continuous KYT monitoring and accountability for failing to prevent fraudulent campaigns.
Enterprises and brand senders, too, are facing new regulatory demands. They are expected to authenticate and register sender identities, as well as ensure lawful, accurate communications. They must also comply with consumer protection and marketing requirements. Non-compliance carries increasing consequences, including blocking, labelling and regulatory exposure.
In several markets, exposure levels approach or exceed around 50% of consumers, confirming that smishing is now a mainstream and persistent threat rather than a niche risk.
Sender identity
The most significant global development is the expansion of sender ID registration regimes, designed to prevent spoofing and impersonation.
In Australia, mandatory sender ID registration and enforcement came into force in July 2026, while registry implementation in Ireland highlighted technical and coordination challenges. France has introduced a co-regulatory model with stricter KYC/KYT and governance requirements, and in Spain and Finland there has been significant movement towards mandatory registration and blocking regimes.
Despite differences in implementation across jurisdictions, a consistent principle is emerging: access to messaging infrastructure increasingly depends on verified identity.
While regulatory models remain geographically diverse, there is a clear convergence around four key principles.
- Identity as a precondition for access
- Proactive fraud prevention, not just reactive enforcement
- End-to-end accountability across the value chain
- Co-regulation, combining public oversight with industry execution
For global organisations, this convergence creates both challenges and opportunities – reducing fragmentation while increasing the expectation for consistent, cross-market compliance standards.
Industry led action
Alongside formal regulation, industry led frameworks are becoming a central component of mobile messaging fraud prevention.
The pace at which fraud evolves means regulatory processes alone cannot respond quickly enough. Commercial, collaborative initiatives – such as sender ID registries supported by industry bodies including the MEF – play a crucial role in translating policy into operational controls.
The MEF registry started operations in 2019 and today operates in various markets, including the UK and Spain. In the UK it monitors roughly 25% of SMS application-to-person traffic from major institutions such as the government, the NHS, the DVLA and others. This industry led initiative is run with the sponsorship of the National Cybersecurity Centre, UK Finance and Mobile UK.
The purpose of these industry led initiatives is that they offer several key advantages.
- Speed and agility: industry driven solutions can be developed and refined rapidly, allowing participants to respond to emerging fraud patterns in near real time.
- Targeted design: controls are built around the specific mechanics of messaging fraud, ensuring they are practical and effective.
- Cross-border implementation: they enable alignment across jurisdictions, reducing fragmentation and closing gaps exploited by fraudsters.
- Regulatory complementarity: they operationalise regulatory requirements, providing scalable mechanisms to implement identity verification and traffic control.
Compliance implications
Compliance professionals should recognise that these developments significantly expand the scope of their responsibilities.
Messaging fraud prevention now requires enhanced KYC and KYT frameworks, verification of customer identity and intent, and continuous monitoring of traffic behaviour. It further demands regulatory mapping and alignment, tracking evolving obligations across jurisdictions. Implementation must also occur across legal, compliance and operational teams.
Maintaining end-to-end traceability of messaging flows – and supporting regulatory reporting and investigation – is also central for data governance and auditability, while due diligence on aggregators and partners (as well as the embedding of enforceable compliance requirements in contracts) are the twin pillars of third-party risk management.
Participation in recognised industry frameworks – such as sender ID registries – is increasingly becoming a demonstrable indicator of compliance maturity, not merely an attractive adjunct. To meet regulatory expectations and mitigate risk, organisations should prioritise implementing unified identity management frameworks aligned with national registry requirements and deploying real-time detection and blocking capabilities for fraudulent traffic.
They should also embed compliance by design in messaging platforms and onboarding processes, and strengthen cross-industry collaboration and intelligence sharing. Crucially, there should be policies and procedures in place anticipating for regulatory enforcement, including audit readiness and incident response.
These represent just some of the steps firms should take to ensure they are not left trailing in the wake of criminal ingenuity or regulatory evolution.
About the author
Stefano Nicoletti is from MEF (Mobile Ecosystem Forum), a global trade body established in 2000 and headquartered in the UK with members across the world. As the independent voice of the mobile ecosystem, MEF focuses on cross-industry best practices, anti-fraud and monetisation. The forum provides its members with global and cross-sector platforms for networking collaboration and advancing industry solutions.