In short
Detection uses traffic frequency, subscriber behaviour, destination diversity, repetitive content, device and SIM behaviour, traffic timing, Sender IDs, network information and other anomalies to identify patterns inconsistent with normal subscriber activity. The strongest single signal is destination diversity: real subscribers message a small repeating circle, SIM boxes message thousands of unique numbers once each.
The behavioural fingerprint
A SIM box is trying to imitate a subscriber but is doing a job no subscriber does. That mismatch shows up consistently across several independent measures, which is what makes detection reliable even as the operators of these systems adapt.
- Destination diversity — a very high ratio of unique destinations to total messages, where genuine subscribers repeat a small contact set
- Reply ratio — near-zero inbound messages, because nobody replies to an OTP
- Content repetition — high structural similarity across messages that differ only in a code or a name
- Timing regularity — even distribution across 24 hours, including hours when a human would be asleep
- Volume — sustained sending far above any plausible personal usage
- Mobility — a SIM that never changes cell, or a group of SIMs permanently co-located
- Group behaviour — many SIMs, often activated together, behaving identically
Why single thresholds fail
Each signal on its own generates false positives. A delivery company's dispatch SIM sends high volume to many destinations. A machine-to-machine device sends with perfect regularity. A call-centre SIM never moves.
Scoring the combination is what produces usable precision. A source that is simultaneously high-volume, high-diversity, zero-reply, content-repetitive, time-regular and immobile is not a subscriber, and each additional dimension sharply reduces the chance of a mistake.
How far automation goes
Much of the process can be automated using rules, behavioural analytics, thresholds, correlation and anomaly detection. Scoring, clustering and alerting should run continuously; no analyst can profile MSISDN ranges manually at network scale.
Confirmation and consequence should not be automated. Disconnecting a subscriber is a serious action with contractual and sometimes regulatory implications, so suspicious cases are escalated for investigation, and enforcement is confirmed by an authorised engineer.
Confirming from the other direction
Behavioural analysis identifies suspect SIMs on the operator's own network. Route testing identifies the problem from the sending side: a test message submitted with a registered alphanumeric Sender ID that arrives at a trap handset from a local mobile number is direct evidence that the route terminated through a SIM rather than through the agreed A2P channel.
Running both directions together closes the loop — the sending-side test identifies which supplier route is doing it, and the network-side profiling identifies which SIM ranges are being used to do it.