KT’s $724M Security Pledge Means One Thing: Zero Trust Must Be Applied to SMS
KT’s $724.5 million security investment is one of the largest in telecom history, and a clear sign that some operators are finally putting consumer protection first. This recent announcement marks a turning point, with Zero Trust, consumer protection, and anti-phishing security beginning to take precedence over conventional defences.
📰 You can read more about their announcement here.
What you’ll learn in the next few minutes
- What the telco industry really means when they say “SMS Fraud”.
- What SMS firewalls really are, and why they fail consumers. They were built to protect operator revenue by blocking unpaid SMS traffic, not to detect phishing. Yet vendors continue to claim otherwise, giving operators a false sense of security while leaving their customers defenceless against scams. MetaCert proved this in live tests across the UK, US, and Australia.
- Cybersecurity vendors are built for consumer protection. They already protect consumers across email, devices, cloud platforms, social media, and mobile apps, and they’re best placed to help operators like KT do the same. Unlike SMS firewall vendors, they bring the mindset, tools, and expertise needed to stop phishing and apply Zero Trust to SMS infrastructure and mobile devices.
💡 KT’s strategy is clear: blocking spam isn’t enough. They’ve recognised what the telco industry has ignored for too long — spam detection is not the same as phishing protection.
🏢 Spam is annoying for consumers, but it leads to revenue loss for network operators.
☣️ Phishing is dangerous for consumers, and leads to stolen identities, drained bank accounts, and malware infections.
Before I explain why SMS firewalls aren’t what you think they are, and why they don’t protect consumers, it’s worth clarifying what the telco industry means by SMS fraud, because that’s probably not what you think either.
SMS fraud isn’t what you think it is
In telecoms, “SMS fraud” refers to marketing vendors and businesses sending messages without paying the proper fees, not scams that target consumers.
Think of Mailchimp as a reputable email platform that enforces best practices for marketing and communication. Twilio plays a similar role for SMS: it enforces strict rules, charges banks, delivery companies, brands, and small businesses for each customer message, and pays mobile networks for every SMS they deliver.
At its peak in February 2021, Twilio reached a market capitalisation of approximately $71 billion. This was driven by rapid growth during the pandemic as demand surged for cloud-based communication platforms, especially for SMS, voice, and app-based messaging. SMS marketing and communications is big business.
Shady SMS marketing providers
Now picture a shady alternative that lets anyone blast out messages at a fraction of the cost by avoiding the fees owed to mobile operators for delivering each message. That’s what mobile networks call “SMS fraud,” not because people are being scammed, but because the network’s being scammed.
Mobile networks call it SMS fraud not because people are being scammed, but because they are.
SMS traffic, including security alerts, 2FA codes, delivery notifications, marketing, and banking messages, generated approximately $73 to $78 billion in 2024 to 2025 and is projected to reach $93 to $109 billion by 2030 to 2034.
Global mobile operators are losing billions every year due to “SMS fraud”, grey-route traffic, and bulk spam. Industry estimates suggest up to 10% of Application-2-Person (A2P) messaging revenue is lost to “fraud”, with more than $50 billion in missed earnings from grey routes over 5 years. In 2022 alone, telecom fraud cost the industry nearly $39 billion, while individual operators faced millions in additional operational costs.
Every unpaid or misrouted message eats into margins in an ecosystem already stretched by regulation, competition, and infrastructure costs. So it’s a revenue stream that operators need to protect with… “SMS Firewalls”.
🚨 This outdated definition of SMS fraud still shapes how the telco industry approaches consumer fraud today, even though unpaid spam isn’t the real threat facing their customers.
SMS firewalls aren’t what you think they are either
The term “firewall” is as misleading as “SMS fraud”. These systems aren’t security firewalls in the way most people assume. They were built to enforce billing rules and block unpaid or misrouted messages that impact operator revenue, not to protect consumers from fake messages with dangerous links. SMS firewalls predate the phishing crisis by years, long before it exploded during the pandemic.
🎓 The Which? report proved what the industry won’t admit: firewalls like Mavenir SpamShield do nothing to stop phishing. They manage routing and billing, not scams — yet operators still refer to them as consumer protection.
SMS firewalls were designed to:
- Analyse business messages
- Detect messages being delivered free of charge
- Protect the mobile operators’ business
SMS firewalls were never designed to:
- Analyse consumer messages
- Detect dangerous links
- Protect consumers from fraud, malware, and identity theft
Why SMS firewalls are not the answer for consumer protection
Ofcom’s (UK telecoms regulator) claim of “98% scam text blocking” is misleading. It refers to spam, not phishing. That distinction matters. The consumer watchdog Which?, supported by MetaCert’s findings, confirmed this distinction.
🎓 MetaCert sent 1,000 unique phishing messages — each with a confirmed dangerous link, to regular SIM cards across all major networks (BT/EE, Three, Vodafone, and Virgin Mobile O2). Not a single one was blocked. Every message was delivered, even when resent repeatedly over seven days.
These weren’t theoretical threats — they were real attacks that bypassed SpamShield — used by every major UK operator. That’s why nobody in the UK is safe from SMS fraud. Firewalls like Mavenir SpamShield exist to protect revenue, not people.
According to Manvenir’s own website under the “Protect Subscribers” section:
Application 2 Person (A2P) text messages are a form of revenue for the CSPs and selling value-added services. While the revenue aspect of A2P is a boon for CSPs, it is estimated that between 5% -20% of all SMS messages are spam or fraud related2.
That has nothing to do with consumer protection.
Subscribers exposed to fraudulent traffic have a poor end-user experience, causing significant revenue loss with missed opportunities and compromising the channel for selling (A2P) value-added services.
Fraudulent, revenue loss, missed opportunities and application-to-person (businesses messages) have nothing to do with consumer protection.
By improving the effectiveness and timeliness of threat detection and responses with Mavenir’s ML-based SpamShield, CSP customers can feel comfortable knowing they are protected with innovative, flexible, rules-based technology where spammers are blocked automatically. SpamShield addresses all major security use cases for messaging channel control for SMS, MMS and RCS messaging protocols.
Rules-based detection is so outdated that even the cybersecurity industry has moved on. And let’s stop confusing spammers with scammers — spam is unwanted, phishing is deception. One is annoying, the other is criminal
Why cybersecurity vendors are the right fit
Cybersecurity vendors specialise in protecting people from phishing. CPaaS platforms like SpamShield focus on billing, routing, and delivery, not security. Consumer protection requires a different mindset, with technology built to detect and prevent real threats. SMS infrastructure was never designed for this. When I led testing at O2, consumer protection wasn’t mentioned once in the 2000s, or the 2010s. That only changed in 2020, when SMS phishing went from zero to widespread overnight.
Only the cybersecurity industry can implement Zero Trust
Effective SMS protection now requires the concept of Zero Trust to be applied within telecom infrastructure. If KT and other operators want a Zero Trust strategy for anti-phishing and consumer protection, this step is no longer optional — it’s essential. And I’m pleased to see KT leading the pack.
Zero Trust is today’s cybersecurity standard. Nothing is trusted by default. People, devices, apps, network requests, and URLs must all be authenticated every time.
Zero Trust for SMS
Sender ID and message content are useless for spotting phishing. Mobile networks can’t verify the identity behind people who use a regular SIM card inside a mobile phone, and there’s no way to tell a criminal from a regular subscriber based on a phone number. Criminals copy real messages word for word. AI and keyword filters can’t tell them apart.
🚨 Any vendor claiming to use AI or keyword scanning to protect people from phishing messages that impersonate legitimate ones doesn’t know what they don’t know.
🎓 Every link must be verified as legitimate. No scoring, no pattern matching, no reliance on past data or AI. Without reliable data, AI has nothing to work with.
How Zero Trust SMS works
- Verified: message delivered as normal
- Unverified: message delivered, link redirected to a warning
- Dangerous: message delivered, link redirected with threat notice
- All links are untrusted by default
What Mobile Fraud Really Looks Like, And How Operators Can Shut It Down
The video below shows SMS phishing from the attacker’s perspective, and what happens when Zero Trust is applied at the infrastructure level. It acts like a kill switch for phishing, blocking dangerous links before they reach a phone, even if the link has never been used, seen, or evaluated before.
Why MetaCert pivoted from conventional security to Zero Trust
MetaCert used to follow the outdated industry standard: threat feeds powered by AI, keyword filters, and databases of dangerous URLs. Most leading security vendors still license our patents for that approach in mobile apps, and we even supplied the data to strengthen their systems. But phishing moves faster than detection, so we pivoted to Zero Trust.
We didn’t invent the concept of Zero Trust, but we were the first to apply it to URLs — treating every link as untrusted until verified.
How Zero Trust SMS stops criminals before the attack begins
When a criminal tests a new phishing link using a regular SIM, Zero Trust treats it as dangerous because it hasn’t been verified as legitimate. Before the message is delivered, the link is replaced with a redirect to a warning page. Even if they generate and test a thousand new links in minutes, every one fails authentication.
🛑 Once they realise their links will never reach anyone, they abandon the attack and move to a network that relies on reported links or AI that pretends to detect danger in a brand new URL with no signs of trust or threat.
Zero Trust SMS has been validated in the real world
MetaCert ran a six-month trial inside a live European operator network. It worked exactly as intended, proving that Zero Trust for links is not just a concept, but a tested solution. The operator is willing to share a testimonial with KT and others. You haven’t seen headlines because it didn’t go live, not due to technical or commercial issues, but because they were waiting on regulatory approval.
It’s time the broader security industry adopted the same approach, and we’re happy to help, just as we used to help with a threat intelligence lookup service.
Zero Trust mobile protection (Link Verifier)
This is the most important innovation we’ve worked on. It brings Zero Trust to mobile by helping people spot impersonators before they open a website, tap a payment link, or download an app. It protects every link, in every app across a device, by showing what’s been verified as legitimate — so decisions are based on facts, not guesswork.
Now live in the AppStore, Link Verifier sits inside the phone’s native share menu. With just two taps, anyone can check any link in any app — SMS, Telegram, WhatsApp, email, browsers, even QR codes, and see instantly if it’s verified, unverified, or dangerous.
It can also be embedded directly inside an app like KT’s or a mobile banking app, giving customers built-in protection from impersonators at the exact moment trust is most likely to be exploited. Instead of teaching people how to spot fake links, Link Verifier gives them a tool to verify each one.
Recap
- KT’s ₩1 trillion commitment shows some operators are now ready to put Zero Trust and real anti-phishing at the centre of consumer protection.
- SMS firewalls belong to a revenue-assurance market. MetaCert’s tests with Which? in the UK, (also carried out in the United States, and Australia) proved they can’t block phishing links.
- True defence demands a security-first vendor who applies Zero Trust to every web link before it reaches the phone.
New EU banking regulation will intensify SMS fraud risks across Europe
From October 2025, new EU rules will require instant payments between banks to process in under 10 seconds, around the clock. This turns SMS phishing into Europe’s real-time attack vector, letting criminals trick victims into vanishing transfers with no delay, no safety net, and no way back. It’s like crypto with no safeguards. Mobile networks are already the weakest link in finance.
Read the full breakdown of our UK test with Which? to see why no major mobile network blocked phishing links, and why it’s time for a new standard in consumer protection.
