Main Image

Why Telcos Are the New Trust Infrastructure

6 min read
INDUSTRY GUIDE
Share on Facebook

70% of the calls and messages arriving on an Indonesian mobile phone come from unknown numbers. Nationwide, seven out of ten inbound communications are questionable. Roughly one in every two SMS messages is either spam or a scam. Promotional SMS click-through rates have collapsed to approximately 1%. The legitimate call answer rate sits at 26%.

In Indonesia, the phone has become an object most users rationally distrust. We know, because we spent six months inside the network helping to fix it.

The trust collapse is global

Indonesia ranks first worldwide in the proportion of spam calls (estimated annual losses between $5+ billion,15-25 million citizens victimized by digital fraud each year). Surveys show 51% of Indonesian scam victims report significant stress or trauma. Fewer than 7% of incidents are ever formally reported.

But the fraud problem is global. The CFCA's 2025 Global Fraud Loss Survey puts worldwide telecom fraud at $41.82 billion, up nearly $3 billion in two years. The FBI's IC3 reported $21 billion in U.S. cybercrime losses in 2025. Deloitte projects AI-enabled fraud will grow from $12.3 billion in 2023 to $40 billion by 2027.

The defenses most operators still rely on were built for a different kind of threat. Static keyword filters, blacklists, complaint-driven takedowns. These methods assume scams are crude and slow to evolve. When a scam campaign can push 100,000 SMSes per hour through spoofed numbers and short-lived domains, formal redress mechanisms that take 14 to 16 days to act have already missed 80% of the financial damage. Only 59% of mobile operators worldwide have even implemented an SMS firewall. Just 51% have a signaling firewall.

Device-level apps like Truecaller and GetContact are, as the LBS case study documenting our Indosat deployment put it, "reactive and did not remove scammers from the ecosystem, leaving the underlying coordination failure intact."

We learned this lesson ourselves. As researchers documented, "scammers adapted faster than rules could be written, and the existing system could not learn autonomously from its own experience." Tightening filters increased false positives. Loosening them let harmful traffic through.

That realization drove us to build Wisely Ai from the ground up as a fundamentally different architecture. One where detection is organized around behavioural pattern recognition rather than keyword matching. Where 10+ AI agents analyze sender reputation, message semantics, traffic velocity, link reuse, and network-level correlations simultaneously. Where the system recalibrates continuously as adversaries adapt.  

What happened when we deployed it

In early 2025, IOH came looking for a partner to help make Indosat the most trusted network in Indonesia. IOH's leadership had already framed digital fraud as a national-scale crisis since more than 65% of Indonesians had experienced spam or scams. They were positioning scam protection not as a feature but as the flagship application of their strategy. We deployed Wisely Ai in roughly three months, integrating directly into IOH's network infrastructure with access to approximately 200 data signals per interaction. We hosted on-premises in Indonesia for data sovereignty compliance.

The deployment launched in August 2025 under the name SATSPAM  (from satpam, the Indonesian word for security guard). Within six months, it scaled from 9 million to 100 million covered users, IOH's entire subscriber base. The system intercepted more than two billion scam and spam communications at 99% detection efficacy with decisions made in milliseconds. Independent Nielsen research scored 83-88% on liking versus a norm of 63, drawn from a database of over 17,000 telco concept tests. 95% of users reported feeling protected.

The commercial results were undeniable. IOH's average revenue per user climbed from a 15.3% year-over-year gain by Q1 2026 over the deployment window. Revenue rose 9%. The case study pointed to a directional ROI of approximately 15-20x, with an estimated 20-40% contribution to ARPU uplift and churn reduction.  

When we discovered that VoLTE penetration on IOH's network was below 30% (meaning most users would never receive network-based caller ID alerts) we independently built an app-based SDK to extend protection. When WhatsApp call volumes ran three to five times higher than traditional telco voice, we added VoIP detection capability. Both features naturally emerged because an AI-native system built for continuous learning can follow the threat across channels.

Regulation followed innovation

In February 2026, Indonesia's Vice Minister of Communication and Digital Affairs attended a public Impact Celebration in Jakarta and encouraged "industry players to implement similar measures." His ministry, Komdigi, subsequently issued a notice to all Indonesian operators to urgently enhance consumer protection, citing the surge in fraud and the substantial financial losses it was causing nationwide.

Our deployment had in effect set the regulatory benchmark.

This inverts the usual sequence. In India, TRAI mandated in February 2026 that operators share AI-detected suspicious numbers within two hours through the DLT platform. Australia's mandatory SMS Sender ID Register takes effect in July 2026. The FCC estimates STIR/SHAKEN delivers a $13.5 billion annual benefit floor. In each case, regulation sets a structural floor. But authentication alone cannot assess intent. AI provides the real-time analytical layer that transforms regulatory infrastructure into a dynamic defense system.

The telcos that treat trust as foundational (embedded in the network architecture, not layered on as a feature) will hold position.

The road ahead

In October 2025, Wisely Ai detected 60.5 million scam messages on IOH's network. Of those, 15 million were IOH-to-IOH. 16.5 million were outbound from IOH to other networks. And 29.5 million were inbound from other networks. We observed that cross-network scam traffic exceeded on-network activity.

One operator's shield cannot eliminate fraud by itself.

What could work is a Threat Intelligence Exchange. A shared, real-time platform through which telcos, banks, fintechs, digital platforms, and regulators would exchange scam intelligence across borders and channels. The precedents exist. Financial institutions collaborate on global payment infrastructure and credit bureaus aggregate borrower data across competitors. When threats are collective, intelligence needs to be collective as well.

That infrastructure does not fully exist yet. We are building toward it. But no single company can will an ecosystem into being. What we can say, from the evidence of a deployment now endorsed by a sovereign government, is that the telcos willing to rebuild their networks as trust infrastructure will define the next era of digital communications. The ones waiting for someone else to go first will discover that the fraud migrated to their network while they were still writing the RFP.