Smart Communications has earned GSMA Open Gateway certification for two anti-fraud APIs — SIM Swap and Device Swap — that let banks, e-wallets, and online platforms check whether the phone number they are about to trust has quietly changed hands. The APIs power SmartSafe NetIdentity, a digital identity protection service offered through PLDT Enterprise's SmartSafe suite.
GSMA is the global association of mobile network operators, and its Open Gateway program certifies that a telco's APIs (application programming interfaces — standard ways for software to request data from the network) follow one worldwide standard. Certification means a bank can integrate Smart's fraud signals the same way it would integrate any certified operator's, anywhere.
What the two APIs actually check
Both APIs target the same scam playbook: account takeover. In a SIM-swap attack, a fraudster takes control of a victim's mobile number — by swapping it onto a new SIM or moving the SIM to another device — and then intercepts the one-time passwords (OTPs) that banks send by text. Once they control the number, they control the account.
According to PLDT Enterprise, the two network signals work like this:
- The SIM Swap API flags whether a mobile number was recently moved to a new SIM card.
- The Device Swap API detects whether a SIM has been transferred to a different physical device.
Either event shortly before a large transfer or a password reset is a classic red flag. A bank that sees it can require extra verification for that one transaction — without adding friction to every login for every customer.
Who can plug into it
The service targets banking, fintech, e-commerce, gaming, and digital entertainment platforms, Back End News reported. The SmartSafe fraud-management suite itself launched in November 2025.
"Digital trust is built in the small moments customers experience every day — when they log in, make a payment, or access a service without worry," said Benedict Patrick Alcoseba, who heads core business management and innovation at PLDT Enterprise.
The certification extends a streak: Smart was the first Philippine telco with a GSMA Open Gateway-certified Number Verification API featuring Silent Authentication, and it earlier certified a RoamStatus API for detecting whether a number is roaming abroad. "Smart's certification demonstrates its commitment to delivering trusted, standards-compliant API services for enterprises," said Julian Gorman, GSMA's head for Asia Pacific.
The plumbing of the anti-scam era
This is telco-side infrastructure for a fight the Philippines is waging on several fronts. SIM-swap-enabled account takeover is a core scam vector here precisely because so much of Philippine banking security still runs on SMS OTPs — the thing these APIs are designed to backstop. The network-level signal arrives as police question whether SIM registration alone has slowed scammers and as regulators push banks toward stronger checks, with the AMLC now screening suspicious transactions with AI.
For consumers, nothing changes on your phone — these are business-to-business services. The effect, if banks and e-wallets adopt them, is that a fraudster who hijacks your number should find it harder to drain your account, because the network itself tells your bank the number just moved. Whether GCash, Maya, and the major banks integrate the certified APIs — and how quickly — is the next thing to watch; no adoption commitments have been announced publicly so far.