Zumigo Blog

Customer Stories: Checking the Line Before They Ever Call

This is the next post in our series on how real customers use the Zumigo platform to solve real problems: a global wealth management firm that checks a phone number for signs of trouble before it ever engages a client through it — not after something looks wrong, but before every call.

Our customer in this story manages money for high-net-worth individuals, and account takeover carries a different weight there than almost anywhere else. The dollar amounts involved mean a single successful takeover can be a dramatic loss on its own. The reputational damage that follows a wealthy client learning their account was drained through their own phone number is the kind that doesn’t fade with a refund. So before this customer engages a client on their device at all, it checks for the specific changes that make an account takeover possible in the first place.

The check run before almost any engagement

The most common of these checks, run across the overwhelming majority of this customer’s activity, is simple to state: has this number recently been ported to a new carrier? A port is one of the clearest ways an attacker severs a number from its real owner — control the port, and every call and text meant for the client now reaches someone else instead. This customer checks that status live, immediately before engaging, rather than trusting whatever carrier record was on file the last time anyone looked.

A second gate before a voice code goes out

For a narrower, riskier action — placing an automated call to read a one-time code aloud — this customer runs a second, more specific pair of checks together: is call forwarding currently turned on for this number, and has the device behind the account changed? Call forwarding is the quiet failure mode here. The number itself can be untouched, never ported, and still ring straight through to an attacker if forwarding has been silently enabled — which would defeat a voice OTP completely without tripping the porting check at all. Pairing that with a device-change read closes the other half of the same question: is anything about how this account is actually being reached different from what it should be, right now, in the specific moment it’s about to matter most.

A pre-engagement gate, not a fraud review

What ties these together is when they happen. None of this is a review that runs after a suspicious transaction — it’s a check that runs before this customer ever picks up the phone or places an automated call, on the theory that the moment right before you trust a channel is the only moment that check is actually useful. A porting or call-forwarding change discovered after the fact is a forensic detail. Caught in the second before a call goes out, it’s the difference between a takeover attempt that fails quietly and one that succeeds.

Why this level of rigor fits the account

This isn’t a check reserved for flagged, high-risk cases — it’s closer to standard practice here, run across nearly every relevant interaction rather than a subset of them. That matches what’s actually on the line: when the accounts behind a phone number can be worth millions, and the client’s trust in the firm is worth more than that, checking constantly costs nothing next to what’s saved by catching the one attempt that would have gotten through.

 

Madhu Vudali is VP, Product Management at Zumigo. Comments or questions? Connect on LinkedIn: @madhuvudali