Flash Call (Flash Call Authentication)

Also known as: Flash Calling, Missed Call Authentication

A flash call is a very short voice call used as a one-time-password mechanism: an application places a call to the user, and the last digits of the calling number act as the OTP that the app auto-detects. Flash calling is cheaper than A2P SMS OTP and increasingly used by OTT apps, but it bypasses operator A2P SMS revenue, disrupts anti-fraud controls and is regulated or restricted in several markets.

Categories: Security ControlsFraudOperations and Business

Flash Call in context

Security controls span signaling firewalls (SS7/Diameter/GTP screening), transport encryption (IPsec, TLS, PRINS), identity and access on OSS/BSS, and monitoring at both packet and log level. Controls are audited against GSMA FS.11/FS.19/FS.20/FS.36.

Telecom fraud costs operators an estimated $40+ billion per year. Common vectors include IRSF, Wangiri callback scams, SIM box bypass, PBX hacking and A2P grey routing.

To place Flash Call in the wider telecom-security picture, review KPI, Billing System, Blue Team, CLI Spoofing, Control Plane Security and EDR — each entry cross-references back to this page so you can walk the topic in either direction.

Related terms

More from the TelcoSec Glossary

Browse the full TelcoSec Glossary, the Ultimate Guide to Mobile Network Security, or the P1 Arsenal of telecom-security tools.