Excerpt 2 from Fraud Handbook
Network Data Fraud: Data Charging Bypass
Data has become the main product for operators, but visibility into the services used has significantly decreased because of encryption and intricate routing. The underlying processes are subtle, and managing them is genuinely challenging. However, preventing large-scale zero-rating fraud is possible with tools that offer accurate insights.
Why Data Charging Bypass Exists in the First Place
Zero-rating is a practice that allows a subscriber to use a specific app or site without the data counting against their data quota. It is not a loophole but a legitimate commercial and practical tool. Operators use it to enable services such as managing subscriptions online and to differentiate in markets where speed and coverage have become commoditized. In parts of Latin America, for example, zero-rated access to messaging apps such as WhatsApp is so embedded in consumer expectations that it is effectively universal across operators.
That commercial reality is exactly why the abuse matters. An operator cannot simply switch zero-rating off without upsetting subscribers and risking high churn. The challenge is how to define, classify, and enforce it accurately, and how to write the terms of service so that genuine use is protected and abuse is not. As we will see, allowing only legitimate zero-rating services is as much a contractual problem as a technical one.
The Cost of Data Charging Bypass for Operators
The primary loss is the revenue not collected when data charging is bypassed. When estimating this revenue loss, the preferred approach is to consider the access cost, specifically the average retail price per GB. According to the ITU, the global average was 2 USD per GB in 2025. There are notable differences, with developing economies averaging around 1 USD and high-income countries at 3 USD. When examining individual countries, the range is even broader, from around 0.2 USD to over 15 USD. This amount represents the potential revenue the operator misses out on for bypassed data and serves as the best indicator of the loss.
If we use the global average in a calculation example and plug in the average data consumption of around 25 GB per month, every user not paying for data would deprive operators of 50 USD per month. 1,000 fraudulent users would cost 50,000 USD per month, and 10,000 fraudulent users would cost 500,000 USD per month.
Not all data accessed for free by fraudsters can necessarily be monetized, so the uncollected revenue would not be quite as high as the example above indicates. But free access boosts usage, and operators still incur costs for transmitting this free data. Expanding networks to support additional capacity involves high expenses, and operational costs like power, network maintenance, tower leases, and staffing also add up. Given that many operators have very slim profit margins, every extra cost is significant.
How much data is consumed fraudulently? There is no global data available, but in customer conversations, the risk has been flagged as high as 1-2% of revenue. The abuse is not uniform across operators and markets, though. Information about vulnerabilities is shared online and can spread incredibly quickly. The relative affordability of data differs between high- and low-income countries, influencing the willingness to pay for data.
A leak that goes viral and is widely abused can quickly drain significant revenue, especially if it is not stopped in time. For a single operator, the absolute value of lost revenue is less important than the contribution to margin and profit. Ultimately, the extent to which an individual operator depends on revenue from data traffic determines the size of the threat. The margin pressure is sharpest in markets with low ARPU.
How Data Charging Bypass Abuse Works
The mechanisms behind zero-rating fraud take many forms, ranging from simple to highly complex. As with most telco fraud, data charging bypass is volatile. Fraudsters move quickly between open paths and refine their methods to avoid detection. When one vulnerability closes, a new one is exploited. The primary methods operators should be concerned about are SNI spoofing and DNS abuse.
SNI Spoofing
When a device sets up a TLS connection, it typically includes a plaintext field with the name of the host the client claims to want to reach. This is the Server Name Indication (SNI) field. In zero-rating fraud, this can be abused by spoofing the SNI, making traffic appear to go to a zero-rated service while the actual payload is routed elsewhere. The charging system then treats the session as exempt, even though the user is effectively browsing or consuming content outside the intended zero-rated scope.
This works if the operator relies too heavily on SNI for traffic filtering. As the list of zero-rated services grows, operators may rely on simpler checks, which makes this method especially attractive to fraudsters. In practice, SNI spoofing is one of the main ways zero-rating is abused.
DNS Fraud
DNS is another major abuse path because it is often zero-rated and treated as low-risk traffic. Fraudsters can use DNS requests and responses as a covert channel, either by disguising data as ordinary lookups or by encoding information into query names and response behavior. Since DNS traffic is widely allowed and frequently inspected less rigorously than application traffic, it can become an easy way to move unauthorized data through the network.
Because DNS requests are often capped at a few megabytes each, the revenue impact is often smaller than that of large-scale SNI spoofing. However, DNS fraud still matters because it reveals a policy gap and can enable data exfiltration and command-and-control traffic in combination with a compromised target. It is therefore both a charging issue and a security issue.
Combined Fraud Patterns
At the more sophisticated end, fraudsters may combine zero-rating fraud with VPNs, proxies, or other techniques to hide the true destination of traffic. In general, the more advanced the method, the more likely it is that avoiding detection, rather than billing, is the primary motivator. This, in itself, is a sign of another kind of threat—one that poses security risks.
Why Zero-Rating Fraud is Hard to Detect
If this were easy to stop, it would not cost the industry as much as it does. Several factors make it genuinely hard, and any honest defense has to acknowledge them.
- The traffic is encrypted. With 95–96% of traffic opaque, the network cannot confirm what a flow contains. Every decision rests on manipulable metadata, not ground truth.
- The landscape shifts constantly. New security protocols (TLS 1.3) and domain lookup (e.g., DNS over HTTPS and DNS over QUIC) remove or obscure information sources that detection previously relied on. A static rule set decays the moment it ships.
- Destinations are fluid. A single service such as WhatsApp may resolve to ten domains and a thousand IP addresses across regional hosting and content delivery networks. Pinning enforcement to IP lists does not scale and breaks constantly.
- The exploits are transient and viral. Each one can be closed once found, but new ones emerge continuously. Fraud teams often monitor the very forums where exploits are shared, but this is inherently reactive and incomplete.
- False positives have a real cost. Block or re-rate a genuine heavy user, or someone legitimately tethering within their terms, and the operator generates a support call, a complaint, and potentially a regulatory question. Precision matters as much as detection.
The Classes of Defense Against Zero-Rating Fraud
There is no single fix. Effective data revenue protection layers several approaches, each of which is useful and each of which has limits.
Contractual: Get the Terms of Service Right First
The cheapest and most overlooked control is the wording of the offer. Many zero-rating terms are written loosely — ‘unlimited free social media’ with no upper bound — which makes genuine abuse almost impossible to challenge and makes the offer impossible to wind back if its cost runs away. The fix is to design the contract and the enforcement capability together: set explicit, enforceable limits rather than ‘unlimited’, and include fair-use and anti-fraud clauses that give the operator discretion to act.
Two real-world examples illustrate this pattern. Claro Brasil shifted from unlimited social-media access to capped bonus bundles, such as offering up to 30 GB for WhatsApp — a generous limit given the average WhatsApp use of about 48 minutes daily, yet it helps limit potential downsides. MTN employs a broad clause that allows it to exclude any customer involved in fraudulent or suspected-fraudulent activity. The main limitation of the contractual approach is evident: modifying terms retroactively can risk customer trust and draw regulatory attention, and a clause is only effective if the network can reliably measure and enforce it. Therefore, contractual language and technical capabilities must align.
Contextual and Behavioral Detection
To effectively combat fraud in encrypted mobile data traffic, a multi-layered strategy is essential. Detection begins by developing a contextual understanding of data usage. Because payload content is hidden, operators need to aggregate network metadata, subscriber information, application classification, and behavioral analytics to form a comprehensive view of service usage. These patterns are monitored consistently over time, enabling rapid identification of any anomalies.
When abnormal activity is detected, the system can trigger alerts, initiate further investigation, or take real-time action on the connection. This enables a shift from reactive fraud handling to proactive detection and enforcement.
Layered Detection Approach
A robust fraud prevention framework combines multiple analytical layers:
- DNS Monitoring: Continuous analysis of DNS traffic (including modern protocols such as DoQ) provides early indicators of misuse. Metrics such as destination IP, query/response size, and request frequency are evaluated in real time using weighted scoring to minimize false positives.
- IP and DNS Validation: Techniques such as reverse DNS lookup help verify that traffic is genuinely destined for the claimed service, reducing the effectiveness of spoofing attacks without relying on static IP lists.
- Application Classification: Advanced classification of encrypted traffic — using packet characteristics, flow data, heuristics, and modeling — enables highly accurate identification of applications and services.
- Behavioral Tracking: Monitoring usage patterns across users, devices, and services allow operators to compare actual consumption against expected norms. Metrics such as session duration, frequency, and data volume help identify anomalies and enforce fair usage policies.
Real-Time Response
Detection must be complemented by the ability to act in real time. Once suspicious behavior is identified, operators can:
- Notify users of potential misuse.
- Throttle or terminate connections.
- Redirect traffic where appropriate.
- Reclassify usage so it is correctly charged against the user’s quota.
Future activity from the same user or IP source can also be flagged for closer monitoring.
Continuous Monitoring and Insight
Fraud often manifests as sudden spikes in usage or transient patterns across specific services. Monitoring aggregate traffic trends — such as unexpected increases in usage for a zero-rated service — helps identify vulnerabilities quickly and supports rapid mitigation.
How Enea Fits In
Enea’s Network Traffic Management portfolio is built to deliver the layers that are hardest to build in-house: accurate classification of encrypted traffic, behavioral modeling, and real-time enforcement. These are key building blocks to prevent zero-rating data fraud.
- Classification of encrypted traffic. Enea’s DPI and traffic classifier infer service and activity from packet, flow, heuristic and modeling signals, reaching around 99% accuracy with regular protocol and signature updates that keep pace with TLS 1.3, ECH and KEM.
- Behavioral fraud detection. Enea’s data fraud prevention combines transport metadata, applied policy, activity classification and longitudinal behavior into a per-subscriber context, then flags deviations (unusual protocols, volumes or timing, or a quota-exhaustion event followed by large DNS responses) and can act in real time.
- Cloud-native scale. Delivered as software (using Vector Packet Processing on platforms such as VMware and OpenShift), the same Layer 3–L7 visibility scales elastically with traffic and network slicing, avoiding the 2N-redundancy licensing and bolt-on complexity of legacy DPI appliances.
The result is that an operator can secure the network against data-charging bypass fraud, optimize how shared capacity is used, and monetize data with personalized and zero-rated offers, without that same flexibility becoming the open door through which revenue leaks.