Our latest news

2nd April 2026

How Fraudsters Bypass Network Simbox and Refilling Controls

Conventional wisdom suggests that bypass fraud is easy to detect:

Execute test calls from external networks into the incoming local network, and if the incoming CLI has been altered, you’ve identified Simbox or refiling activity.

BluGem has delivered active fraud detection services for over 20 years and based on our experience, we can confidently say: this approach is no longer sufficient.

Why Traditional Detection Fails

This method was effective in the early days of grey routing. However, today’s fraudsters are far more sophisticated and they actively design their fraud operations to evade detection.

In some cases, fraudsters even allow detectable traffic to pass through intentionally, creating the illusion that controls are working… while the majority of fraudulent traffic goes unnoticed and here’s how they do it:

1.  Staying Below Detection Thresholds

If a telco sets an alert to detect an increase for a 300 SMS threshold via interconnect routes, fraudsters will simply increase traffic by 299.
They learn thresholds through:

  • Trial and error
  • Insider knowledge

Impact - Fraud that consistently operates just below network detection limits.

2.  Whitelisting Test Number Ranges

Many operators repeatedly execute testing using the same number ranges.  Fraudsters quickly identify these and:

  • Whitelist test numbers
  • Route them correctly (avoiding detection)

Impact - Real customer traffic is still sent via grey routes and incorrectly billed.

3.  IMEI Based Evasion

Fraudsters can also detect the IMEIs of devices used for testing.  If the same devices generate test traffic repeatedly:

  • Their IMEIs are whitelisted
  • Test traffic appears clean

Impact - Genuine users’ devices are not whitelisted and traffic continues to be bypassed.

 

A Different Approach: Undetectable Testing

To stay ahead, BluGem has re-engineered bypass fraud detection to overcome modern evasion techniques.  We still use remotely controlled smartphones and we:

  • Rotate phone numbers
  • Rotate IMEIs

But we go much further….

Introducing the BluGem patented App and Global Crowd

BluGem leverages a global network of over 100,000 real mobile phone users, generating traffic from real devices, in real-world conditions.  Utilising our secure and efficient BluGem app, we can:

  • Execute calls and messages globally
  • Blend seamlessly into genuine user traffic behaviour
  • Eliminate identifiable testing patterns

Why This Approach Delivers Superior Fraud Detection

Fraudsters cannot distinguish BluGem traffic from genuine subscriber activity because:

  • It originates from real users
  • It uses real devices
  • It behaves like normal traffic
  • There are no patterns to detect
  • No ranges to whitelist
  • No devices to filter

Prevent Undetected Fraud Across Your Network

If your current controls rely on predictable testing, fraudsters are already adapting around them.  BluGem’s Patented App combined with our Global Crowd ensures:

  • True visibility of bypass activity
  • Accurate detection of Simbox fraud and grey routes
  • Protection against evolving fraud techniques

If you want to detect bypass fraud, it’s time to upgrade your approach.

News archive