Italy’s new anti-fraud network: more than a case study – a potential model to follow
From telecom payment history to identity-fraud intelligence, authoritative public verification and real-time network APIs, Italy offers an unusually clear view of how fraud infrastructure is becoming layered and cross-industry.
An article written by Nic Balaceanu, CEO of Lendrise
Italy’s New Anti-Fraud Network
From telecom payment history to identity-fraud intelligence, authoritative public verification and real-time network APIs, Italy offers an unusually clear view of how fraud infrastructure is becoming layered and cross-industry.
For years, fraud prevention was relatively easy to explain. A bank knew its customers, a telecom operator knew its subscribers, and a credit bureau knew who paid their loans. Each industry accumulated information, built rules around it and tried to identify bad actors before they caused too much damage. Fraudsters, unfortunately, never respected those industry boundaries. A stolen identity can start with a compromised mobile number, continue with a new service subscription and end with a financial transaction. The same identity, device or phone number can move across several industries within hours.
Italy offers an interesting case study because four very different infrastructures now sit alongside one another: (1) SIMoITel for telecom payment defaults, (2) SIFRID for identity-fraud signals, (3) SCIPAFI for verification against authoritative public records, and (4) CAMARA-based network APIs for real-time telecom signals. They are not one system, and they do not share the same purpose. Together, however, they reveal how fraud prevention may be evolving from individual databases towards several specialised layers of trust.
1. SIMoITel — What happened before?
SIMoITel is perhaps the easiest place to start. Created for the Italian telecommunications industry, it allows participating operators to share information about intentional payment defaults. CRIF was selected by the telecom companies represented by ASSTEL as the technology provider for the platform. It follows a relatively traditional information-sharing model: something happened in the past, that information was recorded, and the history can inform a future decision.
But the distinction is important. SIMoITel is fundamentally about payment behaviour in telecommunications. It is not an identity-fraud database. That boundary becomes particularly interesting when we look at another Italian infrastructure.
2. SIFRID — Does this application look suspicious?
SIFRID, managed by Experian Italia, addresses a different problem. Rather than asking whether somebody has previously failed to pay, the system compares information contained in new applications for products or services with historical application data contributed by participating organisations. Its participants include Fastweb, TIM and Vodafone Italia.
When inconsistencies or anomalies appear, the system can generate an alert indicating potential fraud, while the participating organisation remains responsible for the decision it ultimately takes. Experian explicitly states that an application cannot be rejected solely because SIFRID has generated an alert.
The distinction may sound technical, but it is fundamental: a fraud signal is not a credit decision. Fraud information does not automatically have to become credit information simply because both can appear during the same customer journey.
This is particularly interesting because Experian also operates a credit-information system in Italy. The same technology group can therefore participate in both worlds without requiring the two purposes, credit risk and fraud prevention, to become one and the same. Separate systems do not, by themselves, guarantee appropriate data governance, but they demonstrate that collaboration need not depend on merging credit and fraud information into a single database.
3. SCIPAFI — Is this identity real?
Italy has yet another layer, less visible internationally but particularly interesting: SCIPAFI. Established within the Italian Ministry of Economy and Finance framework and managed by Consap, the system enables participating organisations to verify identity and income information against authoritative databases. Those sources include the Italian Revenue Agency, the Ministry of the Interior, INPS, INAIL and other public administrations.
This is already infrastructure at significant scale. According to Consap, SCIPAFI processed more than 34 million enquiries in 2025, identifying more than 205,000 nonexistent tax codes, over 210,000 documents reported lost or stolen and more than 23,000 cases involving deceased persons.
What makes SCIPAFI particularly relevant, however, is not simply its scale but the perimeter of the ecosystem around it. Participation is not limited to banks and financial institutions. The framework also encompasses electronic communications providers, utilities, insurers, digital identity providers, qualified trust-service providers and credit-information systems.
In other words, the architecture of fraud prevention is already extending beyond the traditional boundaries of individual industries. This does not mean that everybody gets access to everybody else’s data. Rather, it creates a framework in which different participants can obtain specific verification results within defined legal purposes and access conditions.
From databases to real-time signals
The first three infrastructures essentially ask questions using information that already exists. The fourth introduces another dimension: what can the network tell us at the moment the transaction is happening?
4. CAMARA — What can the network tell us right now?
Through GSMA Open Gateway and the open-source CAMARA Project, telecommunications networks are beginning to expose standardised APIs that other industries can consume in real time. Italy is already moving in this direction. TIM and Wind Tre have launched their first CAMARA-based APIs, while the Italian market is focusing particularly on identity and anti-fraud capabilities.
Unlike the other three infrastructures, CAMARA is not itself an Italian database or fraud consortium. It is an international API standardisation initiative that helps make network capabilities accessible through consistent interfaces.
Among the capabilities being deployed are SIM Swap, Number Verification and KYC Match. A SIM Swap API can indicate whether the SIM associated with a mobile number has recently changed, potentially an important signal in an account-takeover attempt. Number Verification can establish whether the phone number being presented corresponds to the device connected to the mobile network without relying exclusively on an SMS OTP. KYC Match can compare identity information supplied during a digital journey with information held by the telecom operator.
These capabilities do not establish identity or fraud on their own. They provide additional evidence that can be combined with other checks.
The difference from the previous models is substantial. A traditional database can tell you something about what happened before. Network APIs can provide a signal about what is happening now. These are not simply additional historical records. They are network intelligence generated close to the moment when a bank, fintech, marketplace or another digital service is trying to establish whether the person on the other side of the screen really is who they claim to be.
The value is not that a telecom operator suddenly knows everything about its subscriber, but that it can answer a narrowly defined question using information that other industries may not possess.
Seen separately, the four infrastructures can look like unrelated initiatives. Seen together, their logic becomes much clearer:
SIMoITel — What happened before? Payment behaviour.
SIFRID — Does this application look suspicious? Fraud intelligence.
SCIPAFI — Is this identity real? Authoritative verification.
CAMARA — What can the network tell us right now? Real-time network signals.
They are four distinct mechanisms answering four different questions, rather than components of a single integrated Italian system. And perhaps that is precisely the point.
The future may not be one giant fraud database
There is an understandable temptation in fraud prevention to accumulate more data: more participants, more attributes, more history and increasingly sophisticated models. Italy suggests another possibility. Perhaps the strongest fraud infrastructure is not the one that puts everything into the same database, but the one that knows which question should be asked of which source, at which moment and for which legitimate purpose.
Credit information can remain credit information. Payment behaviour can remain payment behaviour. Fraud intelligence can remain fraud intelligence. Governments can provide authoritative verification, while telecommunications networks can provide real-time signals.
Technology can orchestrate these different sources without pretending that they are all the same thing or requiring every participant to see every piece of underlying information. Such an architecture still needs clear legal bases, purpose limitations, access controls and accountability. Collaboration does not necessarily mean creating a bigger pool of personal data. It can mean creating better ways of asking specialised sources narrowly defined questions.
This distinction becomes even more important as AI makes document manipulation, impersonation and social engineering increasingly scalable. The traditional response, simply collecting more historical information, may therefore become insufficient. What these Italian initiatives illustrate is the possibility of something structurally different: a movement from the age of the anti-fraud database towards the age of the anti-fraud network, where specialised sources of trust can communicate when there is a legitimate reason for them to do so.
Fraudsters have operated across industries for a long time. Perhaps the most interesting thing happening in Italy is that fraud prevention is beginning to do the same.
Sources
1. SIMoITel — Official website https://www.simoitel.it/
2. CRIF — SIMoITel technology provider https://www.crif.it/news-ed-eventi/news/e-attivo-il-sito-informativo-di-simoitel-la-banca-dati-sulle-morosita-intenzionali-nel-settore-della-telefonia/
3. Experian Italia — SIFRID https://www.experian.it/consumatori/sistema-informativo-prevenzione-frodi-identita
4. Consap — SCIPAFI https://www.consap.it/scipafi/
5. Consap — SCIPAFI 2025 figures https://www.consap.it/consap-a-it-s-all-banking-insurance-2026/
6. GSMA — Open Gateway in Italy https://www.gsma.com/solutions-and-impact/gsma-open-gateway/gsma-open-gateway-italian-operators-unite-to-combat-fraud-and-enhance-digital-security/
7. CAMARA Project https://camaraproject.org/