singtel logo

Article

Network-level caller verification: Defending against voice phishing

The phone remains one of the most trusted channels enterprises use to reach their customers, which is exactly why generative AI voice is being weaponised against it. Effective defence depends on verifying caller identity at the network layer, before the call ever reaches a handset. As deepfake fraud scales across Southeast Asia, the maturity of carrier-level verification and risk-signal capabilities will shape how well the voice channel can be defended.

Categories: Cyber security

03 Aug 2026

16 Mins

/business/insights/network-level-caller-verification-defending-against-voice-phishing.html

Key takeaways

  • AI voice cloning has shifted the question behind every call from "Is this true?" to "Is this caller who they say they are?" Only the network can answer the second.
  • Endpoint defences such as call-blocking apps and consumer awareness training cannot keep pace with increasingly convincing deepfake voices. Verification has to happen upstream of the handset.
  • Layered, network-level controls—including branded caller display, telco-signal APIs and bulk scam filtering—are helping restore trust in the voice channel for banks, government agencies and other customer-facing organisations.

The voice channel under attack

Voice phishing is not new. Fraudsters have long used phone calls to impersonate banks, government agencies or senior executives and persuade victims to share information or transfer money. What AI changes is the quality and scale of that impersonation.
 

Three seconds of audio is all it now takes to clone a human voice. Free online tools can do it in 20 minutes, with around 85% accuracy and rising.1 For two decades, security teams have built the enterprise perimeter around email, web traffic, and login credentials. The phone, however, was never really part of that perimeter. It was a trust channel, the place a bank could still reach a customer, the line a CFO could pick up to authorise a wire. That residual trust is what is now being weaponised.
 

  • Vishing accounts for over 60% of phishing-related incident response engagements globally.2

  • Deepfake voice vishing (voice phishing) surged 1,633% in Q1 2025 alone, and industry projections put deepfake-enabled fraud losses at $40 billion globally by 2027.3
     

The standout case so far is at the engineering firm Arup, where a finance employee transferred $25.6 million across 15 transactions after a video call in which every participant, including the CFO, turned out to be AI-generated.4 The call was indistinguishable from a real one until the money had gone.
 

In practice, this means the question being asked on the line has changed. 
 

  • It used to be: Is what this caller is telling me true? 

  • It is now: Is this caller who they say they are?
     

The first question can sometimes be answered by a careful human. The second cannot. It needs the network.

What the new normal looks like for customers

The impact is particularly visible in Southeast Asia. Singapore lost S$913 million to scams in 2025,5 and the most damaging variant tripled: government official impersonation cases jumped from 589 to 1,762 in the first half of 2025 alone.6 The pattern inside those numbers is the important one: 81.8% of scam losses came from self-effected transfers,5 where the customer authorises the payment themselves after a phone call has convinced them to.
 

For security leaders, this highlights an important gap. It means the bank's authentication system saw a legitimate, authenticated customer making an intended transaction. All internal fraud controls are performed as designed. The breach occurred during a conversation that no enterprise system was monitoring.
 

The collateral damage to legitimate business is now visible. Customer suspicion has hardened to the point where banks, insurers, utilities, and government agencies are watching answer rates fall on calls they need to make. The phone is becoming a channel that customers have learned to ignore, and that is a commercial loss as much as a security one.

 

Why endpoint defences hit a ceiling

The instinctive response is to push the problem to the customer's phone: install a call-blocking app, train them to spot scams, run callback verification procedures. All of these put the burden on the worst-positioned party to bear it. A customer cannot tell, in real time, whether a voice has been cloned. They cannot inspect call routing metadata. Once AI quality crosses the threshold at which human ears stop detecting the difference, no amount of awareness training closes the gap.
 

The carrier sits at a different layer entirely. It can see whether a call genuinely originated from the claimed number, whether the calling SIM is still the one originally registered with the service, and whether a SIM swap happened in the last 24 hours.
 

Branded calling, now live across T-Mobile and Verizon in the US7 and launched by AT&T with TransUnion in early 2024,8 works because the network attaches a verified identity before the call rings on the handset. The same principle is being standardised internationally through the GSMA Open Gateway initiative,9 which gives banks and platforms API-level access to telco data.

 

The network is the verification layer

Consider how a legitimate bank call should land in the new model. It leaves the bank's contact centre carrying a cryptographic identity signature. The carrier, in this case Singtel, validates the signature and displays the bank's verified name and logo on the customer's screen before the phone rings, via Trusted Call.10 The customer can see who is calling with the same network-level assurance that underpins verified SMS. They no longer have to guess.
 

Behind the call, a second layer is doing silent work. SingVerify11 gives the bank programmatic access to real-time telco signals: whether the SIM originally registered with the bank, whether the number has been ported recently, and whether the device is on the network the bank expects. Built on the GSMA Open Gateway framework with authentication partner IPification,9 these signals let the bank's fraud system reach a richer judgement before authorising a high-value action than its own data alone would allow. This is the layer that addresses the self-effected transfer problem directly by introducing a network-side check at the moment the customer is about to act on what they heard.
 

Around both of these sits the bulk-filtering layer the customer never sees. Singtel's Scam Call Protect blocks more than 30 million scam calls and 20 million scam SMSes per month12 before they reach a Singtel subscriber. The carrier is the only position in the call path where filtering at this volume is possible.

What this delivers in practice

  • Customer-facing caller verification: Customers see a verified brand identity on screen before the call rings, removing the need to guess whether the caller is legitimate.

  • Network-derived risk signals: Enterprise fraud systems gain real-time access to telco-side signals such as SIM status, port history, and device network, supporting richer decisioning at the moment of high-value action.

  • Carrier-scale scam filtering: Bulk scam call and SMS filtering runs across the network, blocking known fraudulent traffic before it reaches the customer.


These three layers run alongside existing bank fraud platforms, customer education, regulatory enforcement, and industry information sharing. They address the one part of the stack none of those can reach: the question of who is actually on the line.

 

Restoring trust in the voice channel with Singtel

The market is moving in the same direction. Twilio's 2024 research in Singapore found that 79% of consumers will trust a brand's communication more if it carries a verification badge.13 Consumer behaviour and carrier investment align in the same direction.
 

For ten years, trust in the phone channel has eroded while attacker tools have improved. The next decade will belong to enterprises that can prove who they are when they call, and to the networks doing the proving on their behalf.
 

Restore trust in your voice channel with Singtel.

 

References:

  1. The World Data, AI Fraud Statistics 2026: Deepfake Scams, Losses & Facts, 2026

  2. SQ Magazine, AI Voice Cloning Fraud Statistics 2026: Alarming Trends, 2026

  3. Deepstrike, Vishing Statistics 2025: AI Deepfakes & the $40B Voice Scam Surge, 2025

  4. Trend Micro News, AI Voice Cloning: The Scam That Sounds Exactly Like Someone You Love, 2026

  5. Malay Mail, Singapore police scam cases drop 24.8% in 2025, losses fall to S$913m, 2026

  6. Singapore Police Force, Mid-Year Scam and Cybercrime Brief 2025, 2025

  7. Numeracle, Verizon BCID is Live, 2025

  8. GlobeNewswire, AT&T and TransUnion Launch the Industry's First In-Network Branded Call Display with Logos, 2024

  9. IPification, Singtel Launches Authentication Solution, SingVerify, to Curb Rising Scams, 2024

  10. Singtel, Trusted Call product page

  11. Singtel, SingVerify product page

  12. Singtel, Scam Call Protect product page

  13. Twilio (via Seeking Alpha), Twilio Partners With Singtel to Deliver Secure, Branded RCS Messaging for Businesses in Singapore, 2025

Discover more insights

  1. Singtel named Frost & Sullivan’s 2026 Singapore Cybersecurity Services Company of the Year — Singtel has been recognised for its leadership in cyber security services in Singapore. The award highlights Singtel’s integrated approach to cyber security, combining connectivity, network intelligence and managed security capabilities to help enterprises strengthen resilience across cloud, users, applications and digital infrastructure. Read the full story to discover how Singtel is helping enterprises secure their digital operations with end-to-end cyber security services. /business/insights/singtel-named-frost-and-sullivans-2026-singapore-cybersecurity-services-company-of-the-year
  2. Autonomous defence in BFSI: why the network matters — Banking is moving toward more autonomous cyber defence as agentic AI takes on a growing role in assessing risk and guiding responses. Its impact depends on the ability to enforce decisions consistently across complex, hybrid environments, making the network a critical execution layer. As adoption expands, the maturity of data, cloud, and connectivity foundations will shape how effectively these capabilities operate at scale. /business/insights/autonomous-defence-in-bfsi-why-the-network-matters
  3. Network guardrails for the agentic era — As AI moves from answering questions to orchestrating workflows, enterprises must ensure appropriate governance. One emerging consideration is agentic drift, where autonomous agents act beyond their intended scope. Explore how Singtel’s Unified SASE Convergence platform applies Zero Trust principles at the network layer, treating AI agents as non-human identities with clearly defined access controls. /business/insights/network-guardrails-for-the-agentic-era
  4. Why the future of security is written in your data’s DNA — Security is moving beyond the perimeter towards the core cryptographic layer that defines trust across every transaction, device, and data flow. As quantum computing reshapes the threat environment, the durability of this data “DNA” becomes a true measure of resilience. /business/insights/why-the-future-of-security-is-written-in-your-datas-dna
  5. IDC MarketScape: APAC Managed SD-WAN/SASE Services 2025–2026 — We’re honoured to be named a leader in the IDC MarketScape: APAC Managed SD-WAN/SASE Services 2025–2026. This report offers clarity on where the market is heading, and what a trusted managed SASE partner should deliver. /business/insights/idc-marketscape-apac-managed-sd-wan-sase-services-2025-2026

View all

View all

Stay ahead

Get the latest digest on business and technology trends straight to your inbox.

  1. Business /
  2. Business Insights

© Singtel (CRN: 199201624D) All Rights Reserved