Global telecom security challenges in the 5G era
The transition to 5G technology does not automatically resolve the security issues of previous mobile generations. According to the CFCA Global Fraud Loss Survey 2025, global telecom fraud losses rose to $41.82 billion in 2025, up from $38.95 billion in 2023. This requires operators to implement comprehensive signaling traffic control and cryptographic authentication.
Vulnerability of SS7 and Diameter protocols
The ENISA Threat Landscape 2025 report, based on an analysis of 4,875 incidents, confirms that the exploitation of legacy SS7 and Diameter signaling protocols remains a persistent threat. Operators must regularly audit signaling interfaces, verify routing rules, and configure anomaly detection for incoming requests.
Cryptographic protection and spoofing mitigation
To combat Caller ID spoofing in IP telephony, STIR/SHAKEN technology is utilized. According to the RFC 8224 standard, this approach involves adding cryptographically signed call origin information to the SIP Identity header. Verification is performed on the receiving side using a public key.
At the same time, STIR/SHAKEN is only one component of defense. Comprehensive fraud mitigation requires coordinated efforts between network teams and analytical systems.
Comprehensive fraud mitigation and process optimization
Beyond purely technical signaling-level measures, combating subscription fraud plays a vital role. Operators are advised to formalize customer document verification and staff activity auditing.
To automate related processes, such as document workflow and archiving investigation results, it is advisable to use specialized systems (for example, solutions based on the UnityBase low-code platform by InBase). This ensures role-based access control, activity auditing, and the use of qualified electronic signatures.
Impact on the industry
The continuous rise in telecom fraud losses to over $41 billion directly impacts operator profitability and undermines trust in 5G networks. Legacy protocol vulnerabilities and subscription fraud expose businesses to severe financial and reputational risks, forcing the industry to move away from isolated security measures toward unified, automated cryptographic defense systems.
How to respond
To protect telecom networks and mitigate fraud risks, operators should implement the following practical steps:
- Regularly audit SS7 and Diameter signaling interfaces and configure anomaly detection.
- Implement SIP Identity header verification (STIR/SHAKEN) in accordance with RFC 8224 to prevent Caller ID spoofing.
- Set up cryptographic certificate management processes and integrate network monitoring with SOC and anti-fraud teams.
- Formalize customer document verification and staff activity auditing using specialized automation platforms like UnityBase.
Prepared by a Software Ukraine member. Original publication.