The mobile messaging network has always been more than a technical utility. It is, at its core, a trust infrastructure — the invisible layer that connects operators to subscribers, businesses to customers, and governments to citizens. And right now, that trust is under sustained, sophisticated, AI-augmented attack.
By Valentina Novara, Head of Customer AI & Analytics, Openmind Networks
Openmind Networks, in partnership with SIS International, surveyed 100 senior leaders across mobile network operators worldwide for the Future of Messaging Report 2026. The findings — drawn from C-suite, directors, and senior leaders across product, engineering, wholesale, and commercial functions — paint a clear picture: the fraud threat has fundamentally changed in character, and the industry response must change with it.
The Threat Has Mutated
For years, messaging fraud was a game of known patterns — grey routes, SIM farms, smishing campaigns run by human operators working at scale. Defences were built around rules: blocklists, traffic thresholds, known signatures. That model is now structurally inadequate.
Our own Global Intelligence Insights tell a stark story. AI-powered smishing attacks are now the primary fraud concern for 49% of operators surveyed — and the data behind that number is alarming. AI-crafted smishing messages are generating victim click-through rates 4.5 times higher than conventional attacks. These are not marginally more effective messages. They are categorically more dangerous.
Beyond smishing, the threat landscape has expanded in ways that demand new frameworks. Autonomous AI agents are now being deployed by threat actors — not just to automate attacks, but to execute complex, multi-stage fraud operations without human intervention. Hyper-personalised scams, deep media obfuscation, and single-shot OTP delivery represent attack vectors that did not exist in any meaningful form three years ago.
And as operators have reinforced SMS channels, attackers have pivoted. AIT 2.0 — the exploitation of RCS infrastructure for artificially inflated traffic — is now an active and accelerating concern. The attack surface is not static. It follows investment.
What Operators Are Actually Prioritizing
Operators are not standing still. The report reveals a decisive shift in how the industry is allocating its anti-fraud investment — and where the leading edge of that investment is going.
45% of respondents identified core technology upgrade — specifically network-embedded AI and real-time diagnostics with automated blocking — as their primary investment priority in messaging fraud over the next 12 months. Revenue assurance, focused on the financial impact of grey routes, came in second at 31%. Consumer trust, through smishing detection and prevention, accounted for 21%.
What these numbers describe is a dual strategic challenge that operators are grappling with simultaneously: protecting subscriber trust on one hand, and defending vital messaging revenue streams on the other. The two are deeply connected. An operator that fails on smishing erodes the subscriber confidence that commercial messaging — including RCS — depends on. An operator that leaks revenue through grey routes undermines the commercial case for network investment. Neither can be treated as a secondary concern.
‘Collectively Smart, Internally Strong’
Perhaps the most significant finding in the report is also the most nuanced — and it has direct implications for how operators think about vendor relationships, industry bodies, and their own internal capabilities.
When asked about the optimal approach to tackling fraud, 65% of respondents said collective action is strategically superior — shared intelligence, collaborative threat feeds, and industry-wide blacklists. Yet 32% maintained that operators must ultimately be the gatekeepers, with AI firewalls at the network level providing the final enforcement layer.
These positions are not in conflict. They describe different layers of the same defence architecture. Collective intelligence gives operators visibility into patterns and vectors they would not see in isolation. But intelligence without enforcement is just observation. The operator’s network — and the AI embedded within it — is where that intelligence is translated into real-time action.
The phrase that best captures this consensus is one we’ve started using internally: Collectively Smart, Internally Strong. It reflects where the industry is heading — and the operators who build both capabilities together will be the ones best positioned to stay ahead.
Four Things Operators Cannot Afford To Defer
The report’s findings translate into four clear strategic imperatives:
1. Accelerate autonomous networks. 45% of peer investment is flowing here through AI use cases. Operators not yet planning this are behind the curve on the single highest-priority defence category. The window to close that gap is narrowing.
2. Close the grey route revenue gap. 43% of respondents cite revenue leakage as their second-highest concern. Automated detection tools exist today. Inaction carries a measurable balance-sheet cost that compounds over time.
3. Treat smishing as a trust issue, not just a technical one. 49% rank it as their primary concern. But the risk extends well beyond detection rates. Every successful smishing attack erodes the subscriber confidence that the commercial viability of RCS — and business messaging more broadly — depends on.
4. Invest in proactive enforcement as a competitive advantage. 59% of operators are already deploying AI blocking. Operational experience shows that targeted enforcement forces fraud actors to relocate or abandon routes entirely. Early movers gain a network-level deterrence advantage that is genuinely harder for attackers to circumvent.
The Winning Posture
The messaging fraud landscape is no longer a static set of known attack patterns. It is a dynamic, AI-augmented, multi-channel adversarial ecosystem. Rule-based defences, however well-maintained, will be outpaced. The operators who win will be those who move to continuous, intelligence-led adaptation — across every messaging channel, and at every layer of the network stack.
As Openmind Networks CEO Alex Duncan puts it like this, “in an industry built on trust, the ability to guarantee secure and authentic communication is the cornerstone of long-term commercial success.”
The Future of Messaging Report 2026 is available now on the top banner above. We’d welcome the opportunity to walk through the findings with you and discuss what they mean for your network.