Call Forward Check detects if a mobile number has an active divert – a common tactic used in account takeover fraud. It runs in real time, flagging risk before OTPs or verification calls are intercepted. Silent fraud needs silent defences.
Call Forward Check from Sekura.id detects whether a mobile number has an unconditional call divert active – a known red flag for account takeover fraud. Fraudsters often exploit call forwarding to silently redirect OTPs, banking callbacks or verification checks to a number they control, without the victim ever knowing.
Unlike SIM swap, the customer keeps full signal – making this type of compromise much harder to detect and gives the fraudster a longer window of opportunity.
Fraudsters can bribe phone shop employees to set up an unconditional call divert on a target’s number – or coerce the victim into dialling a short code followed by the fraudster’s number. Once active, all incoming calls, including OTPs and bank callbacks, are silently redirected.
The victim’s phone still has signal, so the compromise often goes unnoticed. Sekura.id’s Call Forward Check detects this in real time, helping stop fraud before it starts by detecting if a call forward is active allowing the transaction to be flagged.
Because the phone remains active and no alerts are triggered, both the victim and the service provider often have no idea the number has been compromised.
OTPs are entered correctly, callbacks appear to succeed, and logins look legitimate. This gives attackers a longer window to operate and makes detection incredibly difficult without network-level checks.
Sekura.id’s Call Forward Check uses live data from the mobile network to determine whether a number has an active unconditional divert in place. The check runs silently in the background, returning a clear result (Pass, Fail, Unknown) in milliseconds.
It’s frictionless, fast, and can be deployed at key moments – login, new payee creation, transaction authorisation or onboarding – to spot risk before it becomes fraud.
Call Forward is part of the Sekura API Framework (SAFr). The response from operators is super-fast, meaning the minimum of delay while your user onboards or logs in.
Since 1991 the humble SIM card has never been hacked or spoofed. The SIM card is the key to Mobile Identity. The 'I' in SIM stands for Identity, after all. There is no more robust technology than the SIM to identity who someone is.
Call Forward from Sekura.id does not rely on active user participation. It's zero intervention and almost-instant confirmation of forwarding status.
A number of other fraud-prevention signals can be added to Call Forward – all delivered through the same single call to the SAFr API. For example, before running a Call Forward check, you might check that it's a valid number first.
Call Forward Check is built for flexibility. You can place the check anywhere in your flow; onboarding, in-life, login or pre-transaction.
Simply pass the mobile number into the API request – we return a straightforward true or false response based on live operator data.No complexity, no noise – just the answer you need, instantly.
Inclusiveness by design - Call Forward maintains the same level of security on IOS, Android or for that matter, any phone - basic handsets, feature phones and smartphones. It's another way Sekura.id is 'humanising' identity.
The cryptographic key and the algorithms in the SIM use the SIM as a secure hardware, a layer of security against a would-be fraudster.
Sekura.id's Call Forward Check is not impacted by the Generative AI, which threatens other authentication methods including biometrics. The SIM is immune from generative AI threats.
Call Forward Check runs silently in the background. The user doesn’t need to enter anything, install an app, or change their behaviour. It simply checks directly with the mobile network whether the number in use has a permanent call divert active. The response takes milliseconds and returns a straightforward result: Pass (no divert), Fail (divert active), or Unknown.
Because it doesn’t interrupt the user journey, it can be placed at critical points like login, transaction approval, or onboarding adding a powerful fraud signal without slowing anything down. If a risk is detected, businesses can step up checks only when needed. That means stronger protection against voice-channel takeover, with zero impact for 99% of legitimate users
Leading banks, fintech platforms, and crypto exchanges use Call Forward Check to protect high-risk user flows—such as login, payment approval, and new payee setup—from covert call-divert fraud. It’s particularly adopted by organisations that still rely on voice OTPs or callbacks and want to ensure the code actually reaches the intended user.
You can also combine Call Forward with other checks like SAFr Auth or SAFr Pulse to be sure the number exists first.
Fraud teams and risk operations integrate the check into their decision engines to add a network-level signal without impacting user experience. Identity platforms and compliance teams appreciate it as part of regulatory-grade authentication — forensic validation of routing integrity, understanding whether a user’s calls are being silently intercepted.
We can give you a sandbox environment to allow you to try Call Forward out.
Our customer, partner, onboarding, technology and delivery teams are all experts, totally knowledgable about what we can do (and what we can’t) and are all yours during your Sekura.id journey, from initial enquiry, to POC, to switching on live service.
Call Forward from Sekura.id is an awesome tool and the service is just as awesome too, we’re pretty confident that once you try both, you won’t look back.
Sekura.id works with the industry’s leading Identity vendors. Be part of our exclusive partner network and add best-in-class mobile identity services to your portfolio.
Already on six continents, we’re on a mission to provide truly global mobile identity coverage, Unlock your mobile network’s potential by working with Sekura.id.
Products
Use Cases
Uniti is Sekura.id’s operator-first monetisation platform that turns Open Gateway APIs into revenue without capex, development, or compliance burdens.