
The API queries the mobile phone operator directly to verify if the phone number associated with an account has changed SIM cards (SIM Swap) or operators (portability) in the last 90 days. It also verifies that the number is valid and active.
The 90-day period is the industry standard and the most critical time window for detecting SIM Swap fraud. In most cases, a scammer will try to use the stolen number shortly after obtaining it. This period is not configurable, as it is the information provided by the operators.
No. Plusmo's SIM Swap API works at the backend level, querying the phone number information directly with the operators. It is totally invisible to the end user and does not require any action, installation, or additional permission from your customer.
The Plusmo API works with a wide and growing network of mobile operators in various regions around the world. At the time of integration, you will be provided with a detailed list of coverage for your target market.
Two-factor authentication (2FA) via SMS assumes that only the legitimate customer has control of their mobile phone. However, SIM Swap fraud overrides 2FA, as the scammer intercepts the OTP code. The SIM Swap API acts before sending the OTP, verifying the integrity of the number to ensure that the device that will receive the code is indeed the legitimate customer.
If a customer has reported the loss of their phone and received a legitimate SIM replacement, the API will report it. In this case, the institution may choose to apply a temporary risk policy, such as a lower transfer limit or a 24-hour waiting period for high-risk operations, until the SIM Swap risk period has expired. This balances security and usability.