Flash Calls: What They Are, Why They Cost You Money, and What You Can Do

Flash calls sit in an unusual position in the telecom fraud conversation. They are not fraud in the conventional sense. The GSMA has formally recognized flash calling as a legitimate subscriber authentication technique. Regulators have not outlawed them. And yet, for most MNOs, undetected flash call traffic represents a direct, ongoing drain on one of the most reliable revenue streams in the business.

 

This post explains how flash calls work, why OTT providers use them, what the revenue impact looks like on the operator's side, and how to think about the two response paths available.

Published:

  • Telecom Fraud
  • A2P SMS
  • Flash Calls

How Flash Calls Work

A flash call is an extremely short, machine-generated call placed to a mobile subscriber for the purpose of delivering a one-time password (OTP) or completing a phone number verification. Instead of sending the OTP as a text message, the originating system encodes the verification code in the calling line identity (CLI) of the incoming call, typically in the last four to six digits of the number. The call rings once or twice and then terminates before the subscriber answers. The subscriber's device or the OTT application running on it automatically reads the incoming CLI, extracts the verification digits, and completes the authentication without any action from the subscriber.

For the subscriber, the experience is frictionless. There is no code to type, no SMS to wait for, and no app to switch between. Authentication completes in the background, often before the subscriber is even aware a call was placed.

According to Juniper Research, operators stand to lose more than $1.3 billion to undetected flash calls cumulatively between 2023 and 2027.

Why OTT Providers Use Flash Calls

The appeal for OTT providers and enterprises comes down to cost. An A2P SMS message routed through official operator channels carries a per-message termination fee, negotiated between the enterprise's CPaaS provider and the MNO. In many markets, that fee is meaningful at scale. An application sending tens of millions of OTPs per month is spending significantly on A2P SMS delivery.

A flash call, by contrast, routes over standard voice interconnect and terminates as a short failed call. The origination cost is substantially lower than an A2P SMS. The call fails before completing, so in many cases no voice termination revenue is generated for the receiving MNO at all. The enterprise gets a cheaper authentication method. The operator gets a call that consumes network resources without generating corresponding revenue.

WhatsApp, Telegram, and a range of other major OTT platforms have used or tested flash calling as a primary or secondary OTP delivery mechanism. The infrastructure to originate flash calls at scale is commercially available, the cost differential is real, and the subscriber experience is competitive with or superior to SMS OTP. That combination makes the adoption trajectory predictable.

What Flash Calls Cost the Operator

Flash-Call-Diagram

The revenue impact falls on two lines: the A2P SMS revenue that no longer arrives and the interconnect revenue that the flash call fails to generate.

A2P SMS is not a marginal revenue stream. Authentication-based messaging has accounted for a substantial share of total A2P SMS volume, and A2P SMS itself has historically represented a meaningful portion of total operator revenue in markets with high mobile banking, digital services, and e-commerce penetration. When a major OTT provider shifts its OTP delivery from SMS to flash calls without any commercial arrangement with the operator, that revenue does not transfer. It disappears.

The interconnect side is more nuanced. A flash call that terminates as a very short, failed call may or may not generate billable events depending on how the network is configured and how quickly the call is terminated. In many deployments, the call is too short to trigger CDR generation. Even where a CDR is created, the call may not match the threshold for chargeable interconnect revenue under existing agreements. The operator has carried the traffic, consumed signaling and switching resources, and generated no corresponding revenue.

The scale at which this happens determines the financial significance. A single OTT platform sending 10 million OTPs per month via flash calls instead of A2P SMS represents, at typical A2P SMS rates, several hundred thousand dollars of annual revenue that has silently migrated off the operator's balance sheet.

The Detection Problem

Flash call traffic is designed to blend in. Short calls from unknown international numbers are not inherently unusual. A busy operator network sees thousands of short, zero-duration, unanswered calls every hour from legitimate sources: sales calls, wrong numbers, calls to subscribers who are temporarily unavailable. A flash call operation is effectively invisible in raw CDR data, which is another challenge for the mobile operator

The existing MNO infrastructure does not have the capability to detect zero-duration flash calls. There are no CDRs for zero-duration calls, and the MNO network is not sized to generate them. Answer Seizure Ratio (ASR) on a voice network usually varies from 20% to 40%. If an operator had to generate CDRs for zero-duration calls, it would mean doubling and upscaling the capacity of the entire CDR system, including the switch, mediation, data warehouse, interconnect, and other downstream systems. That would multiply the cost of the MNO core network and its CDR handling systems.  

Without detection, the operator cannot make a policy decision. You cannot block traffic you cannot identify, and you cannot monetize traffic you cannot classify.

MNOs need to deploy a voice firewall to detect and manage the flash call traffic arriving on their networks.

Two Paths: Block or Monetize

Once flash call traffic is detected and classified, the operator faces a decision between two commercially valid responses. Neither is universally correct, and the right choice depends on the operator's market position, existing OTT relationships, regulatory environment, and revenue mix.

Path 1: Block as unauthorized traffic

Blocking treats flash calls as unauthorized use of the operator's voice network for commercial authentication purposes without a corresponding commercial arrangement. The logic is defensible: OTT providers are deriving commercial value from the operator's infrastructure at below-market rates, reducing A2P SMS revenue in the process.

Blocking does not require the operator to categorize flash calls as fraud in the GSMA sense. It is a commercial policy decision: traffic that circumvents agreed revenue-sharing arrangements can be rejected or degraded. Effective blocking requires real-time classification, because blocking based on retrospective CDR analysis allows significant flash call volume to complete before any action is taken. Operators who block can negotiate directly with OTT providers to establish commercial flash call agreements, converting blocked traffic into a potential new revenue stream under defined terms.

The risk in blocking is subscriber experience, as inconsistent blocking policies can result in false positives and customer complaints. Blocking needs to be precise, and it needs to be paired with a clear communication policy for affected routes.

Path 2: Detect and monetize

Monetization treats flash calls as a billable service rather than a problem to eliminate. The operator detects flash call traffic, classifies it, and generates CDR data that enables charging for flash call delivery in the same way that A2P SMS delivery is charged. OTT providers and enterprises that want to use the operator's network for flash call authentication can do so, but under a commercial arrangement that compensates the operator appropriately.

This path preserves the revenue stream without requiring the operator to take a blocking posture that might affect subscriber experience or create adversarial relationships with OTT partners. It is also more aligned with the GSMA's recognition of flash calling as a legitimate authentication channel. If flash calls are a legitimate service, charging for them is a natural commercial response.

The risk in monetization is that, without enforcement capability, detection alone does not guarantee compliance. An OTT provider who ignores billing for flash calls and continues routing traffic through unofficial channels is generating revenue for the operator only on paper. Monetization requires both detection and the ability to enforce commercial arrangements or reduce the quality of service for non-compliant traffic.

The decision between these paths is not permanent. Some operators block flash calls from providers with whom they have no commercial arrangement while allowing monetized traffic from providers who have signed agreements. That hybrid approach is increasingly common as the flash call market matures.

How Heksagon Addresses Both Paths

Architecture diagram illustrating Heksagon's Flash Call Prevention and Monetization solution, separating OTT and enterprise traffic into unapproved flash calls (blocked), agreed flash calls (monetized), and A2P SMS flows destined for billing.

Heksagon provides dedicated capabilities for each response path, built on the same detection foundation.

Flash Call Prevention handles the blocking path. The solution detects flash call traffic in real time by correlating voice call patterns with A2P SMS traffic data, classifying suspected flash call origination ranges and adding confirmed sources to grey lists for partial blocking or to blacklists for full blocking.

Flash Call Monetization handles the revenue capture path. Once flash call traffic is detected and classified, the solution generates CDR data for the identified flash call volume, enabling the operator to bill for flash call delivery. Operators can configure selective whitelisting, permitting flash call traffic from OTT providers who have commercial agreements while maintaining blocking for non-compliant sources. This gives the fraud and commercial teams a shared operational framework for managing OTT authentication relationships.

Both solutions operate within the same detection engine, which means an operator's policy on flash calls can evolve over time without rebuilding the underlying classification infrastructure.

Block or Monetize, or Both: It’s Up to You

The two paths are not mutually exclusive, and many operators end up combining them.

With the global decline of A2P SMS traffic and enterprise inclination for cost-effective OTP channel usage, flash call monetization presents a great opportunity in the market for operators to open new revenue streams. In many markets, operators remain skeptical, treating flash call monetization as cannibalization of A2P SMS revenue and refusing to accept smaller revenues because flash call pricing is lower than SMS. The delay in decision-making may result in loss of this opportunity or even loss of lesser revenues. Hence, operators have to act quickly.

Your decision depends on factors specific to your operation: which OTT providers are generating flash call traffic on your network, what proportion of your A2P SMS revenue is at risk, whether your regulatory environment has guidance on flash call treatment, and what commercial relationships you have or want to develop with OTT authentication providers. If you would like to assess your current flash call exposure and which path fits your network today, speak with our team.