Heksagon Helps Kcell Block 700,000 Fraudulent Flash Calls a Month & Turn Bypass Traffic into Revenue
- Client: Kcell
- Sector: Mobile Network Operator (8+ million subscribers)
- Region: Central Asia (Kazakhstan)
- Challenge: Flash call volume growth, A2P SMS bypass
- Solution: Heksagon Flash Call Prevention, Flash Call Monetization
- Result: ~700,000 fraudulent flash calls blocked per month, ~$10,000 per month in flash call monetization
Published:
The Challenge
Flash calls cost mobile operators money in a way that is easy to miss at first. An OTT platform or bank initiates a call to a subscriber purely to deliver an authorization code via the incoming caller ID, then hangs up before the call connects. No SMS is sent, no voice minute is consumed, and no termination fee is collected. For the operator, the call looks like abandoned international traffic. The revenue loss is invisible in standard reporting.
Kcell, Kazakhstan's leading mobile operator with over 8 million subscribers, faced this problem at scale. Flash call volumes were growing in line with the expansion of A2P authentication across the region, and the revenue that should have flowed through legitimate A2P SMS channels was instead being bypassed entirely. The operator needed a way to detect flash calls accurately, block fraudulent ones at volume, and ideally redirect a portion of that traffic back to monetizable channels without disrupting service for genuine callers.
The challenge was not simply building a block list. Flash call sources change frequently, operate across shifting number ranges, and some proportion of incoming calls that look like flash calls are legitimate first-time callers. Any solution that sacrificed accuracy for coverage would damage customer experience.
The Solution
Kcell and Heksagon designed a three-layer detection architecture, with each layer targeting a different class of flash call traffic and feeding a shared database that drives real-time routing decisions.
Active detection through automated testing: Bots continuously initiate A2P authorization code requests, capturing the MSISDNs (mobile subscriber numbers) of flash callers as they respond. These numbers are analyzed by Kcell's database layer and pushed immediately to Heksagon for action. This daily testing cycle keeps blacklists current and feeds profiling algorithms that can identify entire number ranges rather than individual numbers, reaching claimed 100% accuracy within identified ranges.
Passive detection through traffic analytics: Two profiling processes run in parallel. A daily profiling job monitors frequency, duration, and call pattern data in real time to catch emerging threats. A monthly profiling job runs a deeper retrospective analysis across millions of call records to surface hidden, long-term evasion schemes that daily monitoring would miss. Together, they allow the system to detect threats that are actively mutating to avoid detection.
Deterministic detection through calling subscriber profile: Every incoming international call is checked against an Access List of numbers that have previously called the Kcell network. Numbers with no prior contact history are dropped automatically, creating a zero-trust barrier for unidentified traffic sources. Kcell measured the callback rate on dropped calling subscriber profile at 0.8%, meaning the false positive impact on genuine callers is minimal and operationally manageable.
What Heksagon Does in the Architecture
Heksagon Flash Call Prevention solution sits at the center of the traffic management layer. It takes the classified data from Kcell's database and applies routing decisions in real time, without requiring operator intervention on each call.
Incoming traffic is distributed across three lists. Numbers confirmed as legitimate are passed through on the Whitelist. Numbers identified for further handling are placed on a Reroute list, where they can be directed toward a monetizable A2P channel. Numbers on the Blacklist are dropped immediately.
The routing decisions update automatically as detection data changes. When active testing adds a new number to a blacklist, or when profiling updates a range classification, Heksagon applies the change to live traffic without manual steps in between. This closed loop between detection and enforcement is what allows the system to operate at the volumes Kcell handles daily.
Results are surfaced in a Power BI dashboard that tracks blocked and passed calls, reroute volumes over time, and the distribution of outcomes across loss, recovery, and prevention categories. The technical events of routing are translated directly into financial metrics, making the impact visible to both fraud management teams and commercial stakeholders.
The Results
Within the deployed Heksagon-powered architecture, Kcell achieved the following outcomes:
- ~700,000 fraudulent flash calls blocked per month: This is the total volume of unauthorized flash call traffic removed from the network on a monthly basis.
- ~$10,000 per month in flash call monetization: Blocking alone recovers money by stopping bypass. The monetization figure represents the additional direct financial result from converting flash call traffic into a billable channel rather than simply dropping it.
The callback rate on the calling subscriber profile held at 0.8%, which Kcell treats as the acceptable cost of a zero-trust policy applied to all new international traffic.
Facing the Same Challenge? What This Means for You
Flash calls are a revenue problem that looks like a traffic problem. The operators who address it most effectively get the power to treat detection and monetization as a single architecture rather than two separate decisions.
The Kcell deployment illustrates why that matters in practice. Blocking alone recovers revenue by stopping bypass. But without a reroute mechanism, blocked traffic simply disappears. With one, a share of it returns to a billable channel. That difference is what separates a protection investment from one that generates a measurable financial return.
Heksagon's Flash Call Prevention handles the detection and blocking side through real-time traffic analysis and automated list management. Flash Call Monetization extends that by enabling operators to bill for flash call termination rather than simply blocking it. It converts what was a grey-route bypass problem into a new A2P revenue stream. If your network is losing A2P SMS revenue to flash call bypass and you want to understand what a detection and recovery architecture looks like for your specific traffic profile, contact Heksagon.