This is the first post in a new series where we highlight how real customers use the Zumigo platform to solve real problems. We’re starting with a story about authentication at the point of payment — the split second before money moves.
Our customer in this story is a Fortune 500 digital payments platform operating at global scale, processing an enormous volume of consumer transactions every day across multiple continents. At that scale, fraud isn’t an abstract risk to plan around — it’s a constant, evolving pressure that shows up in real transactions, every single day.
In short: this customer no longer relies on a single check at the moment of purchase. They’ve built a layered stack — SIM change and porting status, name-and-address validation, prepaid/postpaid status, and device history. The result: a 90%+ catch rate on known fraud. Here’s how that stack came together, and why calling these signals in combination matters.
There’s a specific moment where fraud prevention has to work: the instant a customer clicks “buy” on a large purchase. Everything the platform knows about an account matters less than one narrow, urgent question — is the person completing this specific, high-value transaction actually the account holder?
That’s the problem we solve, and over the past year, this customer’s usage of our platform has grown dramatically — as the signals we provide have become core to how they stop fraud at the exact point it happens. Crucially, the signals continue to be valuable as this customer’s geographic footprint expands beyond the US and Canada into Europe.
Fraud evolves. That’s a truism in this industry — even more so with AI providing the tools to fraudsters. That said, Zumigo’s real-time contextual signals help thwart fraud. With this payments platform, the customer has built on what they had, continuing to layer signals on top of each other to create a much fuller real-time picture at the moment of purchase.
Name-and-address validation, the traditional KYC staple, is a good example of how this works in practice. Today it plays a complementary role: rather than standing alone as the primary check, it now runs as a secondary layer that follows a SIM change check: first confirm whether the phone number tied to the account has recently been moved to a new SIM, then confirm the identity details still line up. That’s not a case of one check replacing another. It’s a case of the customer discovering that the checks are more powerful stacked than standing alone.
The same layering shows up around the carrier relationship more broadly. Alongside SIM change detection, the customer now regularly checks whether a number has recently been ported to a different carrier altogether, whether the line is prepaid or postpaid — a detail that correlates with fraud risk in its own right, and whether the device itself has a history of being swapped out from under the account, via IMEI checks. Together, they build a live composite of the phone and carrier relationship behind a transaction — exactly the picture a static identity check was never designed to provide.
The clearest sign of how deliberate this layering has become is in how the checks get called: account info, device, and SIM signals now regularly fire together in a single transaction. That’s a customer that has moved from calling on individual signals to calling on a coordinated stack of them, purpose-built around the moment a high-value purchase is about to complete.
It’s worth being precise about what this looks like in practice, because the term “authentication” gets used loosely. This isn’t identity verification in general — it’s a step-up check that triggers specifically around high-value purchases, at the exact moment a fraudster is most motivated to act and a legitimate customer most needs protecting.
When a purchase crosses a certain threshold, the customer’s system checks the SIM before it ever sends a one-time code — confirming the number hasn’t recently been ported or swapped before relying on it for verification. That order matters: it tells the payments platform something a password never can — whether the phone in the transaction is still, in fact, the phone that belongs to the account.
It’s a small piece of friction placed exactly where it matters most, and invisible everywhere else.
None of this layering would matter much if the underlying signals weren’t predictive. That’s the other half of this story: these signals have proven highly predictive of fraud, catching more than 90% of known fraud cases.
That number is arguably the real headline here, more than any usage figure. Layering more signals together only helps if the signals themselves are catching what they’re supposed to catch. A 90%+ catch rate on known fraud is what makes the rest of this story credible — it’s the reason a customer would choose to build an entire authentication strategy around these checks in the first place, and why they’ve kept adding more of them.
The highest-stakes moment in any payment flow is the one right before a large, irreversible transaction completes. Stopping fraud there requires a check built specifically for that moment: one that looks at the state of the phone and the carrier relationship in real time, right at the point of purchase.
That’s the thread we’ll keep pulling on in this series — not abstract security concepts, but specific moments where a customer needed to know, with confidence, that the person in front of them was who they claimed to be. Authentication for payments is just the first chapter.
Madhu Vudali is VP, Product Management at Zumigo. Comments or questions? Connect on LinkedIn: @madhuvudali