New security challenges in telecommunications and contact centers
With global telecom fraud losses projected to reach $41.82 billion by 2025, telecom operators and enterprises are rethinking their security strategies. Traditional contact centers built on monolithic BSS/OSS systems face vulnerabilities in VoIP traffic. In particular, subscription fraud costs the industry $5.31 billion annually. Delivering effective customer service requires integrating innovations into a secure, signaling-level protected core.
Anatomy of vulnerabilities and the transition to Open Digital Architecture
Modern contact centers often rely on fragmented API integrations, creating poorly secured touchpoints. The lack of robust authentication in VoIP allows attackers to spoof customer calls. Furthermore, the exploitation of legacy SS7 and Diameter signaling protocols makes traditional verification methods, such as SMS passwords, unreliable.
To securely deploy AI agents instead of monolithic systems, TM Forum's Open Digital Architecture (ODA) concept is proposed. ODA features a component-based, API-first architecture where AI tools connect as independent microservices via standardized open interfaces. This allows organizations to control the context of AI requests and restrict data access in compliance with the AI Act.
Cryptographic protection and IRSF mitigation
To protect against Caller ID spoofing, the IETF RFC 8224 (SIP Identity) standard is used. It involves adding cryptographically signed call origin information to the SIP header. While this standard addresses number authentication, it does not protect against device compromise or social engineering.
Another threat is International Revenue Share Fraud (IRSF), where attackers hack SIP accounts to route high volumes of calls to premium rate numbers. To mitigate IRSF, strict routing rules must be implemented: blocking international destinations by default, disabling unauthorized forwarding in IVR, and monitoring traffic in real time.
Core modernization and the technology platform
For large operators, transitioning from a monolith must occur without disrupting business processes by creating a secure integration layer. Low-code platforms, such as UnityBase, serve as the technological foundation for designing cloud-native architectures. Thanks to a unified domain model, the platform enables rapid generation of REST APIs to connect AI agents and securely link new digital channels with legacy systems, ensuring row-level security (RLS) and detailed transaction auditing.
What it means for companies
The vulnerability of traditional contact centers to subscription fraud and Caller ID spoofing threatens both corporate revenues and customer trust. As telecom fraud losses escalate toward $41.82 billion, businesses that fail to secure their VoIP traffic and API integrations face severe financial damage from International Revenue Share Fraud (IRSF) and compliance failures under modern data regulations like the AI Act.
Action plan
- Transition to Open Digital Architecture (ODA): Deploy AI agents as independent microservices via standardized open APIs to control data access and maintain compliance.
- Deploy Cryptographic Protection: Implement the IETF RFC 8224 (SIP Identity) standard to cryptographically sign call origin information and prevent spoofing.
- Enforce Strict Routing Rules: Block international destinations by default, disable unauthorized forwarding in IVR, and monitor traffic in real time to mitigate IRSF.
- Modernize with Low-Code: Use platforms like UnityBase to build a secure integration layer, enabling row-level security (RLS) and detailed transaction auditing without disrupting core business processes.
Prepared by a Software Ukraine member. Original publication.