A Real Fraud Problem, Solved at the Network Layer
On July 13, 2026, Vodafone launched Number Verify 2.0 in Germany, the Netherlands and the UK — the first markets in what the company calls a global rollout of a network-level phone authentication API (Vodafone newsroom). Instead of texting a six-digit code that a user copies into a login box, the API asks the mobile network itself to confirm that the SIM in the device making the request matches the number the app expects. No code, no waiting, no typing — and, critically, nothing for a phisher to intercept.
The fraud problem this targets is not hypothetical. In the UK, Cifas's National Fraud Database recorded unauthorised SIM-swap cases surging roughly 1,055% in 2024, with identity fraud tied to mobile accounts up 87% the same year (Cifas). SMS one-time passcodes are trivially phished, socially engineered, or SIM-swapped away from their owner. As Vodafone's Director of Network APIs, Johanna Wood, put it in the launch announcement:
"SMS OTP has been the default for over a decade, but it was never built for the threat environment we operate in today."
She's right, and regulators evaluating this technology should start from that premise rather than treating it as a novelty to be viewed with reflexive suspicion.
How It Actually Works
Number Verify 2.0 is built on CAMARA, the Linux Foundation-hosted set of standardized telecom network APIs now backed by more than 65 operators through the GSMA Open Gateway initiative. Technically, the app calls the API with a claimed number; Vodafone's network "probes the SIM in the device the app is running on" and returns a cryptographically-backed true/false match, without exchanging the user's personal data between the app's systems and the network (Vodafone Developer Blog). That design choice matters under the GDPR's data-minimisation principle — processing should be "adequate, relevant and limited to what is necessary" for the stated purpose (EU Regulation 2016/679) — because a true/false match token is a narrower disclosure than, say, handing a retailer the subscriber's registered address. The service is explicitly framed as PSD2-compliant, functioning as a genuine possession factor for strong customer authentication in payments.
The Steelman for Caution
Before endorsing this outright, it's worth stating the strongest objection fairly: a telecom operator sitting silently in the authentication path for banks, retailers and government services is a meaningful expansion of the carrier's role. GDPR consent must be "a clear affirmative act" that is "freely given, specific, informed and unambiguous" — not a background checkbox buried in a login flow a user barely notices (EU Regulation 2016/679). If Number Verify's consent screen becomes as reflexively clicked-through as a cookie banner, the "consent" that legitimises the data flow risks becoming theatre. Dutch and EU regulators, including the ACM as the Netherlands' telecom-market supervisor, are right to expect operators to keep that consent step meaningful, not decorative (ACM).
Why the Concentration Risk Matters More Than the Privacy One
On privacy narrowly defined, CAMARA's no-PII-exchange design and multi-operator interoperability actually undercut the case for heavy intervention — this isn't a single vendor building a walled garden. The sharper risk is concentration of a different kind: because SIM-swap fraud already works by compromising the carrier relationship (usually through social-engineered porting), binding authentication more tightly to the SIM makes a successful carrier-side compromise more valuable to attackers, not less. Where a phished SMS code fails against one account, a defeated Number Verify check could silently pass an attacker through every connected bank, retailer and government service at once — with no code typed, and no moment for a wary user to notice something is wrong. CAMARA's companion SIM Swap Detection API, also at general availability, is the necessary complement here, and any bank or platform adopting Number Verify 2.0 without pairing it to swap-detection checks is building on an incomplete foundation.
Where This Should Land Regulators
The Netherlands is simultaneously building the EU's alternative to carrier-anchored identity: under eIDAS 2.0, every member state must make a European Digital Identity Wallet available to citizens by 24 December 2026, with relying parties required to accept it from December 2027 (EU Regulation 2024/1183). That wallet, not a telecom carrier, is meant to be the neutral, portable identity layer citizens control directly. Number Verify 2.0 and the EUDI Wallet aren't in conflict — one authenticates a phone number instantly today, the other will eventually let users assert broader identity claims without any operator in the loop — but Dutch and EU regulators should resist letting carrier-bound authentication become the default simply because it shipped first. The proportionate path is not to restrict Number Verify 2.0, which solves a real, quantified fraud problem without the walled-garden risk that would justify heavy-handed rules. It's to require genuine, unbundled consent screens, mandate swap-detection pairing for high-risk relying parties like banks, and keep the EUDI Wallet on schedule as the operator-independent alternative once it arrives.