Use case · Fraud prevention with SIM Swap

Stop account takeover after a SIM swap

When a fraudster moves a victim's phone number to a new SIM, they start receiving the victim's one-time passwords and can reset accounts or approve payments. Ooredoo's network APIs let you check the line before you trust it.

Register to get API keys and start building

How it works

  1. Before a sensitive action

    Before a login from a new device, a password reset, a payment or a payout, call SIM Swap check with the phone number and a time window (maxAge, in hours).

  2. If the SIM changed recently

    Pause the action and ask for stronger proof: in-app confirmation, a document check or a call. Use retrieve-date if you want the date of the last swap to apply your own rule.

  3. If it did not

    Continue as normal. For a smoother check, confirm the number silently with Number Verification instead of sending an SMS code.

APIs for this use case

Questions

How recent a SIM swap should count as risky?

You decide. The check operation takes maxAge, a window in hours, and answers whether the SIM was swapped within it. retrieve-date returns when the SIM was last swapped, so you can apply your own rule.

Does the user have to do anything?

No. SIM Swap is a server-to-server call on the phone number. The user sees nothing unless you decide to ask for more proof.

Which standard does it follow?

SIM Swap, Number Verification and OTP follow CAMARA, part of the GSMA Open Gateway initiative.

Other use cases: Phone number verification · Direct carrier billing · Get started

Contact Us

Please use this form to email us regarding anything related to Ooredoo

Fields mark with an * are required
First Section
Second Section