Use Cases
Enhance Authentication Security for High-Risk Transactions
Confirm the phone — and the person — before granting access.
The Challenge
When a password reset request is issued, or when a business needs multi-factor authentication to keep accounts safe from hacking and breaches, an additional authentication method is required — something that confirms phone ownership and possession, or device enrollment, beyond the credentials themselves.
The challenge is doing this without pushing the OTP to a device the fraudster controls, or adding so much friction that legitimate users abandon the reset or login altogether.
How Zumigo Solves It
Zumigo can issue one-time passcodes (OTPs) by SMS link or voice call to verify that the mobile phone number belongs to the consumer and that the device is in the hands of the same person. Upon entering the passcode, Zumigo compares the existing customer’s name and address to the name and address on file with the carrier and returns a set of risk signals and scores. Specifically:
- With SMS link, Zumigo can passively authenticate the mobile number in session, without requiring the user to manually type a code
- Before sending any passcode, Zumigo can first assess account takeover risk on the phone number, so the code isn’t handed to a compromised device
- As an additional method, Zumigo can authenticate the consumer’s identity using passkey technology installed within an enrolled device that has been paired with the consumer’s account
- Any of these methods can be layered with other verification and authentication approaches for higher-value transactions or accounts—in particular, Silent Network Authentication or SIM-Based Authentication
How It Works
- A password reset or step-up authentication event is triggered.
- Zumigo assesses the account takeover risk of the phone number before issuing anything.
- An OTP is sent via SMS link, voice, or email, or the enrolled passkey is checked — whichever method fits the risk level and channel.
- Upon successful verification, Zumigo compares name/address to carrier records and returns risk signals, confirming the reset or login can proceed safely.
Related Products
- Assure Authentication: The core product covering silent network authentication, OTP delivery, and passkeys.
- Assure Insights: Pre-checks account takeover risk before a passcode is issued.
- Assure Identity: Confirms name/address match against carrier records as part of the authentication event.
Why Zumigo
- Verify the account owner is genuinely in possession of the phone before granting a reset or high-risk action
- Improve consumer experience during account opening or sign-in with seamless, low-friction authentication methods
- Satisfy Know Your Customer (KYC) requirements when consumers volunteer their phone number for authentication
- Assess risk before issuing a passcode, closing the door on SIM-swap-based OTP interception
FAQ
What authentication methods does Zumigo support for MFA?
Zumigo supports OTP delivered via SMS link, voice call, or email, as well as passkey-based authentication using a device’s secure enclave, and can layer these with SNA/SBA.
How does Zumigo prevent OTPs from being intercepted during a SIM swap?
Zumigo can assess account takeover risk — including recent SIM swap or porting activity — before issuing a passcode, so a scammer’s device is less likely to receive an OTP meant for the legitimate owner.
What happens after the OTP is entered?
Zumigo compares the existing customer’s name and address to the name and address on file with the carrier and returns risk signals and scores, adding an identity-matching layer on top of possession verification.
Can passkeys replace OTP entirely?
Yes, for enrolled devices. Passkey technology can authenticate the consumer without an OTP step, and can be layered with other methods for higher-risk scenarios.