• At Orange, the Orange LiveNet business unit, in collaboration with its partners, offers a dedicated API (application programming interface): “Trust Signals.”
• Partners invited to a webinar moderated by journalist Jérôme Bouteiller joined Orange to assess the current situation and discuss B2C (Business-to-Consumer) and B2B (Business-to-Business) solutions.
The situation is worsening, warns the CNIL
A study by Surfshark shows that France is the second-most affected country in the world by data breaches (passwords, usernames, phone numbers, addresses, Social Security numbers, banking information).
“Because it serves as the gateway to our digital lives, the cell phone number is the primary target for fraudsters,” explains Alexandre Zermati, Product Manager for Anti-Fraud Identity APIs at Orange LiveNet. Fraudsters use it for smishing (SMS messages containing a link that is actually malicious), vishing (calls made using a spoofed number), SIM swapping (to take control of a SIM card), and theft (interception of the one-time password sent to confirm an action on an app or website). “The good news is that the cell phone can be our best defense.”
Jean-Pierre Lim, Head of Product at DQE (“Data Quality Everywhere”), confirms: “A cell phone number is more robust than a simple identifier, such as an email address, which can be highly vulnerable to fraud and easily compromised.” However, the context is one of industrialized and automated attacks, which are leading to a resurgence in fraud.
The fintech company Pledg, which specializes in installment payments, is working to minimize vulnerabilities, explains its Chief Operating Officer Robin Devals. One method involves reducing the amount of data customers are required to enter.
Camara APIs – Trust Signals
This is where the operators’ APIs, brought together by the Camara initiative, come into play. Camara APIs provide essential tools to strengthen security and combat fraud. Orange LiveNet, for example, offers the “Trust Signals: Your Toolkit to Combat Identity Fraud” API.
- KYC Match. This “Know Your Customer” API verifies the information entered by the user when signing up for a service. It cross-checks the first and last names against the operator’s data. It helps detect inconsistencies and attempts to open fraudulent accounts, while streamlining the customer journey. Regarding consent, it relies on legitimate interest to process personal data without explicit consent.
- Number Verification. This API replaces the SMS OTP by verifying that the phone number used for authentication is indeed the one on file with the app. This reduces lthe number of authentication steps and improves security and the user experience. User consent is required for version 2.1, but not for version 1.0.
- SIM Swap. This API detects a recent SIM card change, indicating a potential fraud risk. It is popular mainly in the United Kingdom and the United States, where it is used in conjunction with other signals to improve the scoring engine.
An Effective and Expanding Solution
These Camara APIs work well, explains Alexandre Zermati: standardized, they are available from 291 operators worldwide, covering 80% of global connections. Pledg, notes Robin Devals, plans to deploy these APIs in 20 European countries by 2027, starting with Portugal, Spain, Italy, and Germany. Standardization facilitates easier international deployment, with APIs already available in Spain and Germany, concludes Jean-Pierre Lim. Soon, additional signals, including KYC Tenure, will help improve decision-making.
This text has been translated by an artificial intelligence.
Read more :
Fintech identity fraud is evolving. Network “trust signals” are becoming the missing layer
Trust Signals webinar (YouTube, in French)
One-time password, an SMS containing a code for identity verification in the context of mobile telephony.

