The future of phone number authentication

To embed our video on your website copy and paste the code below:

<iframe src="https://www.youtube.com/embed/3oriDCMLPqA?modestbranding=1&rel=0" width="970" height="546" frameborder="0" scrolling="auto" allowfullscreen></iframe>
Guy Daniels, TelecomTV (00:24):
Welcome to our special webinar on the future of phone number authentication, brought to you by the GSMA. Hello, I'm Guy Daniels. The mobile number is still one of the strongest signals we have for proving who we are online. NumberVerify 2 is a new seamless service that enables users to authenticate their number with a single tap, eliminating friction while proactively preventing social engineering attacks. And today, with the help of Vodafone, BT and Virgin Media O2, we're going to learn more about NumberVerify 2 and see it working live in a demonstration. We're going to start by discovering why phone number authentication needs to move beyond SMS OTP, then we'll look at the benefits of NumberVerify 2 and also compare the various SIM authentication methods available. Then we'll see NumberVerify 2 in action with a demo, before highlighting the next steps for aggregators.

(01:33):
So let's get started and meet our guests. Joel Douglas, Product Lead, Network APIs at BT Group. Adri Loloci, Senior Product Manager of the Vodafone Group Network API portfolio. And Murray Findlay, Head of Messaging and Payments at VMO2 Wholesale Mobile. Hello, everyone. It's good to see you all. Thanks so much for taking part in today's webinar. Adri, let me come to you first — because we've been successfully using SMS OTP for years. Why do we need to move on?

Adri Loloci, Vodafone Group Network API Portfolio (02:13):
Thank you. So as you rightly said, SMS OTP has been used for a number of decades. Whether you are a social media platform, a banking app, or any app for that matter, you're relying on SMS OTP today for various reasons — whether that's two-factor authentication or contacting users when they're signing up. SMS has been incredibly successful for decades, but the threat landscape has evolved significantly since then. There are a number of challenges with SMS OTP and I'd like to go through each of them. One is social engineering. Because the user is essentially receiving a one-time PIN code by SMS, we have actually seen a lot of cases where the user can be socially engineered — they sometimes hand over these SMS OTP codes over the phone. There are also interception and SS7 risks, which are less likely.

(03:17):
However, social engineering has been a huge, huge problem.

(03:22):
There's also friction, because when the user receives an SMS, there is some waiting time — this can range from seconds to sometimes minutes, depending on coverage. And when AutoFill works, it's great, but sometimes it doesn't work, so the user has to type the code manually. Another important point is that businesses typically pay for an SMS that is delivered, but not every SMS that is delivered results in a successful authentication. Sometimes the user is impatient and clicks to resend, and so businesses are actually paying for each SMS that is delivered — whether or not it leads to a completed authentication. This actually increases the cost of authentication for those enterprises. So these challenges have prompted us to work on the next generation of authentication — one where the user can, with a single tap, share their phone number with the developer they wish to, just as simply as they sign in with Google or Apple, without the risk of harm or the need for SMS codes.

(04:40):
So that's what we've been working on.

Guy Daniels, TelecomTV (04:42):
Thank you very much, Adri. Who's driving this move beyond SMS OTP — is it the operators, or is it the business customers?

Adri Loloci, Vodafone Group Network API Portfolio (04:50):
That's a great question. We have actually been collaborating globally with the GSMA to create a new standard under CAMARA. We've been collaborating also with system and operator vendors to create this next iteration. So operators globally have actually designed the specification.

Guy Daniels, TelecomTV (05:15):
Fantastic. Thanks for that. And it's a perfect link into Joel now — Joel, if I can turn to you, can you explain more about what NumberVerify 2 is and outline the benefits that it brings?

Joel Douglas, BT Group (05:27):
Yeah. So as Adri has mentioned, we're really looking to revolutionise the SMS OTP authentication market. And NumberVerify 2 is that next evolution. It's a very attractive value-based proposition. The way it works is it seamlessly authenticates your device on the network — so there is no need for a code, there is no need for a text message, and it has an incredibly high success rate. In the past with SMS OTP, quite often that might fail, or your customer might actually drop out halfway through the journey. What this does is keep the customer in that journey — apart from that initial click, no further action is needed from them. This provides a much better customer experience, it'll result in fewer failed attempts, and for the business themselves, it'll actually gain traction and keep the customer in the ecosystem.

(06:20):
It gives a higher conversion rate, and there's no way for a fraudster to intercept it. As Adri also mentioned, it's really strong on fraud prevention. We've seen loads of examples across the industry of social engineering, spoofing, interception, and SMS pumping. And what this product really does is eliminate a lot of that type of fraud. And as mentioned, working with CAMARA and Open Gateway, all the UK operators are really scaling this in the UK — but also with the vision that this will be an international solution. So just like SMS OTP, customers will be able to go to a one-stop shop and get their number verification.

Guy Daniels, TelecomTV (07:02):
Joel, thanks very much. And all three participants in this webinar are from UK operators. I was going to ask about this — you're looking at the UK here in this example, but presumably it does scale globally and operators in any country could adopt this. But is it important for all operators in a particular territory to adopt this?

Joel Douglas, BT Group (07:25):
So I think fraud is everywhere — it's not a UK-specific problem. And I think as operators, we definitely have the capability to implement this in the UK, but also to help achieve the international standard that's needed. So this is something that should be available in every country.

Guy Daniels, TelecomTV (07:45):
Great. Thanks so much, Joel. And let me move across to Murray next, because I'd love to know how NumberVerify 2 compares with SMS OTP as well as the first iteration of NumberVerify.

Murray Findlay, Virgin Media O2 Wholesale Mobile (07:59):
Yes, okay. If you'll allow me to set a little bit more context around that — my role involves me in lots of things. Messaging in the traditional sense, SMS, the newer way of delivering messages over RCS, and APIs is just another extension to the products and remit that I have. So operator-based services is the way I like to think of these things. Telcos are regulated, they're trusted implicitly by their customers, and are strategically focused on protecting their users — with a stated intent to 100% eliminate consumer harm through the prevalence of fraud, exposure of individuals to age-inappropriate content, and tightening security via the network controls we can now all invoke through our advanced infrastructures. We're really progressing these aspirations through tangible initiatives via both the GSMA and government programmes such as Open Verified Communication and the Second Telco Fraud Charter.

(08:56):
What I can say from my perspective is that I see the positive effect of all of this — the general improvement of integrity and security in all services — in the way that we're invoking a consistent approach to security, brand validation, and generally improving integrity across all of our services through my involvement in SMS, RCS, and API business now. The way that APIs, and this particular one, will change the market is this, in my view. Operators have had great success — and both Joel and Adri would attest to this — in bringing APIs to market over the last few years, which today have delivered additional trust signals, facilitated pre-checks, contributed to risk scoring, and exposed potential account takeover scenarios. However, NumberVerify 2 will now place the SIM as a capability at the heart of a single-factor authentication process. It provides secure and silent authentication while also addressing current security vulnerabilities and user experience issues, as Joel has already articulated.

(09:57):
It achieves this by authenticating the user of an app or an online service by checking if the phone number they provide matches the one that's been assigned by the network to the device they're currently using. Other authentication solutions require multiple steps, cause high abandonment rates on apps, and impact conversion and user experience adversely. So what is it about our property — the mobile phone number, the MSISDN — which makes it such a great component to sit at the heart of this? Well, mobile numbers are the most ubiquitous, unique and durable identifiers in the digital era. The phone number is the most used digital identity and processing factor. Telcos can provide and underpin secure MSISDN authentication with their infrastructures, and you can use your MSISDN as a safer and simpler mechanism than passwords, authenticators, passkeys and SMS OTPs. There's no user onboarding required as it's all automated by the network and the provider of the service on top of the network, and any service with a SIM can make use of an assigned MSISDN.

(11:01):
So it has absolute ubiquity and absolute ease of use. Authentication today is based on multiple steps — you need to be something, you need to know something, and you need to have something. And an OTP by SMS is delivered as a means of you demonstrating that you possess the phone with the number that you've asked the code to be sent to. So number verification in this globally recognised and supported standard has evolved with the use of what we call an operator token. An operator token is an encrypted, non-persistent and anonymous identifier that allows a third-party app to authenticate a device with an operator. Your app can either ask the user to insert their phone number, or ask permission to access it via the operator — and that's when the operator token is generated behind the scenes to support this activity.

(12:02):
Number verification is applicable to a host of different use cases for the purpose of fraud prevention and detection, including sign-in authentication of a user, login security enhancement, transaction confirmation, password reset validation, fraud risk assessment, or compliance assurance by automating the identity checks needed to meet regulatory standards for secure authentication processes. With the APIs that we have in market at the moment, we have what we call Number Verification version 1. The benefits of that over SMS are that you can invoke a single-factor authentication process. But at the moment with the Number Verification version 1 standard in the market, we can only really address up to around 50% of the use cases that we'd like to. Having said that, Number Verification, even in its current form in market today, means there's no need to wait for an SMS for authentication because it happens in the background.

(12:58):
There's no need to switch screens, there's no user interaction, there's no need to enter a PIN — the MSISDN as a unique identifier works up to three times faster than OTP SMS verification does today. It also removes the opportunity for social engineering attacks, as no PIN is needed — there's no step that a fraudster could intervene in and act in a social engineering capacity. Number Verification 2.1, which is the new standard that we're focusing on today, is a natural evolution of the current Number Verification 1.0. It works regardless of the connection the phone or device has to the network — so it can work on Wi-Fi and over VPN; it doesn't have to be registered on the cellular network. The native OS supports it, and an SDK can be embedded into the device app to support fallback services via SMS or lower regulated number verification services.

(14:01):
It works across all devices. User consent is covered by the operating system with no adverse effect on the user's experience, and it can work on a multi-SIM device — with OS-native SIM selection. And it can be used for authentication in a whole host of ways. I guess that's where I'd like to land. I'm in no way disparaging the use of SMS — I regard SMS as an important operator-based service — but clearly, logically, we need to look to evolve the market and help address the known problem statements that businesses have: how do we evoke a better user experience? How do we make this faster, more reliable, and more secure? And that's exactly what Number Verification plays into — both in its current iteration, Number Verify 1, and the one that will be available very shortly, Number Verify 2.1.

Guy Daniels, TelecomTV (14:53):
Great. Thanks very much, Murray, for that. I can't help but notice there's a versioning scheme here — 1.0, 2.1. Is there therefore a planned roadmap to keep adding features and benefits as it progresses?

Murray Findlay, Virgin Media O2 Wholesale Mobile (15:06):
Yeah, it roughly equates to that. The first phase of Number Verification 2 will be 2.1, which means it's going to work natively on Android devices and support all the capabilities of Android. Apple will have slightly different standards embedded into their operating system, and the next phase of Number Verify 2 will probably be called 2.2, which will have a native working version that will be seamless for iOS devices. So yes, to some extent, you're right — we're going to name these by the versioning convention schemes that we know from software today. So that's the implication of that.

Guy Daniels, TelecomTV (15:53):
Fantastic. Thanks very much, Murray. Well, you've all set the scene. We've covered the challenges of today's solution, we've looked at the benefits of an enhanced approach and looked at the available options. So can we now see NumberVerify 2 in action? Adri, I'm going to hand over to you — let's have a look at the demonstration.

Adri Loloci, Vodafone Group Network API Portfolio (16:13):
This is a very familiar screen that users are used to seeing when they sign up for a new account — in this case for a bank, or similar. I've created an app called Green and Protein, which is a food delivery app, and the journey I'm about to show is the user sign-up journey. So typically, you might have seen that a user can sign up with Apple or Google, or in this case they also have the option to sign up with their phone number. So what I'm starting now is typing the phone number — this is how the user would normally begin this journey.

(16:49):
And what you can see at the top is a timer that I've added so that you can see how long this journey typically takes for the user when everything goes right and the number is in a well-covered area. So in this case, I received the SMS OTP which has already been pre-filled, and I click "Verify and continue." As you can see, the user can now continue to put in their name and the rest of their details. But if you look at the top, it took around 30 seconds to get the phone number confirmed for this app. And what I'd like to show you is how this would look with NumberVerify 2. So it's as simple as "Continue with your phone number." You will see the prompt from the operating system asking, "Do you want to share your phone number?" The user clicks yes, and in this case it took five seconds.

(17:48):
So as you can see in this example, it was more than five times faster to get to the phone number confirmed. And this is the journey that we're trying to deliver to developers. It's one tap, there's a native OS consent screen asking the user for permission to share their phone number — this is exactly what happens when the user is sharing camera roll access, microphone access, or location. These are prompts from the operating system that the user is extremely familiar with. And in this case, this prompt was used to share the phone number. So we're incredibly excited for developers to start using this and to report on whether they've seen higher conversion rates and reduced instances of social engineering, given that there is no code to share with NumberVerify 2.

Guy Daniels, TelecomTV (18:45):
Adri, that is fantastic. Really, really fascinating. It'll be interesting to see, as you say, what business customers' reaction is — it's very clear in terms of convenience and, as you say, hopefully reduced fraud and social engineering attempts. So what's next? Can you take us through the next steps that aggregators need to take to start deploying this?

Adri Loloci, Vodafone Group Network API Portfolio (19:10):
Yeah. So I'm just going to recap some of what Murray also mentioned. We are starting with Android — so this is first going to be available on Android, and we hope that Apple soon announces support. We don't have any commitments on this, but we're hoping to create a solution that has coverage across both major operating systems, Android and iOS. So we're starting first with Android, and this is going to be available for our aggregator community. All the existing aggregators that today are serving SMS OTP journeys can actually implement NumberVerify 2 natively and it will work as shown. One of the things they need to keep in mind — and this is slightly technical — is the Android consent screen. I've just shown an example of how Google Firebase, which is one of our aggregators, is showing the consent screen.

(20:14):
The top part, highlighted in red, is actually fixed by the operating system — so the aggregator will keep this text unchanged. What they need to keep in mind is that the bottom part — the provider terms — actually has to be updated. In this case, we have the suggested text that we're using: "Allow your carrier to share your phone number with the app. The app may use your phone number to manage your account and provide services subject to their privacy policies." So this is the text that will come through the consent screen, and the user will see that reflected in their user journey. The second thing — also slightly technical — is that the aggregator will have to be registered with Android. Android will maintain a whitelist of aggregators who are able to invoke the TS4 token and therefore the consent screen that you see here.

(21:11):
And therefore there will be a SAN — Subject Alternative Name — that will be provided by each of the mobile network operators to Android, to whitelist them to be able to display this natively within apps. So these are the first two major steps that developers will need to complete. And then obviously the rest of the documentation for integration will be available in the developer portal of each of the mobile network operators. And because we are using the same standard, the documentation should be consistent between operators as well — so aggregator integration should be as straightforward as possible.

Guy Daniels, TelecomTV (21:56):
Great. Thanks so much. And can I just pick up on the whitelisting there for a second, Adri? So it's the operating system that manages it, but the operators themselves provide those domains?

Adri Loloci, Vodafone Group Network API Portfolio (22:07):
So the operating system is effectively facilitating the integration between the aggregator and each of the mobile network operators. The whitelisting is simply a way for the mobile network operators to tell the operating system: "Yes, I do recognise this as an aggregator — therefore they are able to control that token and therefore that consent screen pop-up," because this will only be accessible to the partners that each of the mobile network operators choose to work with.

Guy Daniels, TelecomTV (22:40):
Thanks so much, Adri. And a final question to all three of you — what's the commercial status of this, not only in the UK but also globally? I'll come to all of you, but Adri, I'll start with you.

Adri Loloci, Vodafone Group Network API Portfolio (22:53):
Thanks. So for Vodafone, we are commercially live today in the UK, Germany and the Netherlands, and then we have three other European markets which we'll make available in the next two months, which we'll announce shortly. And our aim is to cover our entire worldwide footprint by the middle of next year.

Guy Daniels, TelecomTV (23:17):
Great. Thanks, Adri. And Joel, I'll ask you the same question.

Joel Douglas, BT Group (23:21):
Yeah, sure. So BT Group will be live this year with NumberVerify 2. And what I really want to point out is what we're showing here as a group of MNOs — how we're really coming together. We do have a bit of a track record of this, and hopefully in the future we'll continue to collaborate and really put trust back into the networks.

Guy Daniels, TelecomTV (23:43):
Great, Joel. That's really good to hear. Thanks very much. And Murray, final word to you.

Murray Findlay, Virgin Media O2 Wholesale Mobile (23:47):
Yeah. In a similar vein, we've got Number Verification version 2 coming towards the end of the year — it should be available by the start of Q4. One of the benefits of having a global standard, as alluded to, is that it can enable deployment in multiple territories. The standard itself engenders a different conversation between us all, because clearly we want to enter a territory in a consolidated manner — we all want to be in the market delivering a ubiquitous service that delivers the same customer experience for every phone user in our country. So we're very much working in lockstep on this, and that's one of the big benefits. And as I say, that therefore creates a massive appeal for hyperscalers and for the larger enterprises that operate not only nationally but more internationally.

(24:43):
So it's all good news.

Guy Daniels, TelecomTV (24:45):
It is. And I look forward to following its progress. Well, thanks everyone. We must leave it there. Thank you all very much for taking part today. If you'd like further information on this topic, please follow the links below the video. You can also get in touch with any of the companies from this webinar — just complete the contact form on this page. For now though, thank you for watching and goodbye.

Please note that video transcripts are provided for reference only – content may vary from the published video or contain inaccuracies.

Webinar

SMS one-time passcodes have become the default way to prove control of a mobile number, but they were not built for today’s threat landscape or customer expectations. Number Verify 2, part of the GSMA Open Gateway initiative, offers a different model: Network-based authentication that confirms the relationship between number, SIM, device and user without ever exposing a human-readable code that can be intercepted or phished. In this webinar, experts from Vodafone, BT/EE and Virgin Media O2 explain how the new standard works and give a live demonstration of Number Verify 2 in action. 

Broadcast Live July 2026

Participants

Adri Loloci

Senior Global Product Manager, API Hub, Vodafone

Joel Douglas

Senior Product Manager for Network APIs, BT/EE

Murray Findlay

Head of Messaging & Payments, Virgin Media O2 Wholesale Mobile