White Paper Excerpt

Excerpt 4 from Fraud Handbook

Network Voice Fraud: International Revenue Share Fraud

Voice remains a high-value, high-settlement service, and its economics run on interconnect: operators pay one another to originate and terminate calls, and international and premium-rate destinations carry elevated charges. Voice fraud targets exactly these settlement flows, and it is unusually well represented on the money-out side of the ledger. It frequently causes the operator to pay real cash to a counterparty, which is what makes it so damaging.

Why IRSF Exists

International Premium Rate Numbers (IPRNs) are not inherently fraudulent. They were designed for legitimate value‑added services where users pay a higher per‑minute or per‑call fee, and part of that revenue is shared with the service provider. It is essentially a billing mechanism for paid voice-based services, spanning advice, entertainment, participation, and digital content.

IRSF is a classic tactic in telecom fraud, involving the manipulation of International Premium Rate Numbers to receive outpayments. Fraudsters trick others into making costly calls to these numbers. Over time, they have refined their techniques to continue their schemes despite enhanced defenses and intelligence efforts. Nowadays, the methods used to generate calls and evade defenses are highly diverse, posing significant challenges for operators’ protection and intelligence gathering.

IRSF results in substantial direct losses for operators because they must cover the costs of unauthorized international call traffic. It is often regarded as the most financially damaging type of fraud for operators. Estimates suggest that the annual losses from IRSF range from $5 billion to $10 billion. In a recent survey, operators identified IRSF as their primary fraud concern, with reports of increasing volume and financial impact. Once thought to be a problem mainly for emerging economies, IRSF is now recognized as the most harmful fraud type even in developed countries.

How IRSF Actually Works

Before fraudsters can start generating calls, they must ensure those calls reach a premium number from which they can receive payments. This requires cooperation from other malicious actors.

First, an IPRN provider must supply the premium number. While some IPRN providers operate legitimately, many do not. The latter not only ignore how the numbers are used but some even actively support fraudulent activities by providing services to facilitate fraud. A common service is to offer a test framework that allows fraudsters to verify whether their number will be routed to the IPRN and that calls to it will not be blocked, thereby generating revenue. Since many operators actively block known fraudulent calls, there’s no guarantee that IRSF calls will reach their destination as intended. This service exists solely to support fraud.

Second, fraudsters require an operator or transit carrier to route calls to the IPRN or to short-stop them. This step is essential because it allows the use of any number for fraudulent activities. Typically, transit carriers passively support fraud by ignoring call-routing details and relying on least-cost routing. Less frequently but potentially more dangerous, an intermediary actively participates by offering artificially low routing fees, capturing traffic from upstream sources, and forwarding it directly to the IPRN. In some cases, a complicit intermediary even short-stops calls by terminating them, often using IVR to stretch the call, then collecting the premium rate without paying the required termination fee for the premium number.

Often, a single rogue actor assumes multiple roles. A transit carrier might control the IPRN, or the IPRN provider might also be involved in the fraud targeting their own number.

PBX Hacking

PBX hacking is one of the most common IRSF entry points. Attackers exploit weak passwords, misconfigurations, or unpatched vulnerabilities in enterprise phone systems (PBX/VoIP). Once inside, they program the system to generate large volumes of outbound international calls, typically outside business hours to avoid detection. These calls are routed to high-cost IPRNs controlled by fraudsters, who receive a share of the termination fees. Because the traffic originates from a legitimate enterprise system, it appears genuine to carriers, allowing fraud to continue until abnormal billing or usage patterns are detected.

Wangiri (One-Ring Scam)

Wangiri fraud drives victims to unknowingly generate IRSF traffic. Fraudsters place short, missed calls (“one ring”) to large numbers of users, prompting them to call back out of curiosity. The callback reaches a premium-rate international number linked to the fraud scheme. Each returned call generates revenue, even if it lasts only a short time. This method leverages human behavior rather than system compromise, making it highly scalable. It is often combined with automated dialing systems to target thousands of users simultaneously and funnel traffic to IPRNs.

Stolen or Hijacked SIM cards

Fraudsters acquire or compromise SIM cards, often by theft or by creating fake/subscription accounts, and use them to generate high volumes of international traffic. These SIMs may have prepaid credit or unlimited calling plans, making them ideal for automated dialing campaigns. Calls are directed to IPRNs, generating revenue shares for the attackers. Because the traffic originates from legitimate subscriber accounts, it is difficult for operators to distinguish from normal usage initially. Fraud rings may also use SIM boxes to scale this activity, distributing calls across many SIMs to avoid detection thresholds.

Malware

Malware enables IRSF by silently taking control of devices or systems to generate fraudulent traffic. On smartphones or computers, malicious apps can initiate calls or send messages to premium-rate numbers without user awareness. In enterprise environments, malware may help attackers gain access to telecom infrastructure (e.g., VoIP servers) or automate call generation. In some cases, malware works alongside phishing or credential theft to compromise accounts used for telephony services. This approach allows fraudsters to scale operations while remaining hidden, as the traffic appears to originate from legitimate users or devices.

Why IRSF can be Hard to Detect

Throughout the long history of IRSF, fraudsters have evolved their techniques and created numerous variants to evade detection. Meanwhile, the interconnected landscape has grown into a complex network of hubs and aggregators. As a result, identifying IRSF has not become easier, it has become more challenging.

  • From an operator perspective, IRSF looks like normal phone calls. IRSF traffic is hard to distinguish from legitimate calls because it appears identical. Fraudsters use valid, assigned number ranges, routing through the same paths as legitimate calls, and using throttling and number cycling to avoid detection. Traditional rules like blocking invalid ranges no longer work, as most attacks now target valid destinations. As a result, operators must rely on behavioral analysis rather than simple filters, thereby increasing complexity. When fraud blends into normal traffic, it persists longer before being identified, resulting in greater losses.
  • Transit carrier complexity makes it hard to find culprits. International calls pass through multiple carriers and networks, meaning no single operator has full visibility of the end-to-end route. When fraud occurs, pinpointing where it was introduced requires coordination across several parties and regions. This slows investigations and makes accountability difficult. Fraudsters exploit this fragmentation by inserting IPRN providers into routing chains, effectively hiding within legitimate infrastructure.
  • It’s often too late when detected (speed matters due to per-minute costs). IRSF losses accumulate quickly because charges are based on call duration. Automated systems can generate large volumes of calls in a short time, resulting in significant financial damage within hours. Detection often relies on thresholds or billing analysis, which introduce delays. By the time fraud is identified, substantial losses may already have occurred, making real-time detection essential. Typical premium number fees in IRSF are between $1-$30/min, with some going even higher. A moderate campaign with 100 concurrent calls at $10 per minute, running for 8 hours, would result in a loss of $480,000.
  • False positives. Detecting IRSF risks flagging legitimate traffic, especially since valid numbers and real usage patterns are often involved. Knowing not only when to flag a number but also when to release it and allow calls to it again is paramount. Blocking legitimate traffic can disrupt customers and harm trust, so operators cannot apply overly aggressive controls. This forces a balance between prevention and service quality, allowing some fraud to slip through. Minimizing false positives requires more advanced analytics, increasing system complexity and operational effort.

Classes of Defenses Against IRSF

Number Reputation and Intelligence Feeds

The foundation for IRSF defenses is to use fraud intelligence feeds that maintain real-time lists of known bad destination numbers. This is not the same as keeping track of premium rate numbers, since any number can be used in IRSF schemes through various mechanisms. When a call is attempted, the system checks the destination against these reputation databases and can block or throttle traffic to flagged numbers. These feeds often come from industry consortia, fraud prevention vendors, and shared operator data. The main advantage is fast detection of known fraud patterns without needing to analyze traffic behavior.

Traffic-Pattern Anomaly Detection

This method uses statistical analysis to identify unusual calling patterns that suggest IRSF activity. Systems monitor metrics such as sudden spikes in international call volume, abnormal call duration distributions, repeated very short calls (flash calls), unusual hours of activity, and traffic concentrated on specific destinations. Machine learning models can detect patterns that rule-based systems miss by learning baselines of normal behavior for subscribers and routes. The strength is detecting fraud using behavioral indicators rather than relying solely on destination lists. However, limitations include difficulty distinguishing legitimate business traffic surges from fraud, especially during promotional events or holidays. MNOs face trade-offs between detection sensitivity and false positives. Aggressive anomaly detection can block legitimate customer calls and degrade service quality. Additionally, sophisticated fraudsters can “train” systems by gradually increasing activity to avoid triggering sudden-change alerts.

Velocity and Threshold Rules

Velocity rules set explicit limits on call frequency, duration, destination concentration, and traffic bursts from specific sources like subscribers, trunks, or interconnect partners. For example, an MNO might block a subscriber making more than 20 international calls per hour or throttle traffic exceeding 500 minutes to a single destination country. Breaching thresholds can trigger automatic alerts or temporary blocking. The advantage is simple, predictable enforcement that works well for obvious fraud bursts. However, limitations include fraudsters operating just below thresholds to avoid detection and the need for constant rule tuning as business patterns change. MNOs must trade off strict enforcement against customer friction. Overly restrictive velocity limits can inconvenience legitimate high-volume users, such as tourists or business travelers. Rules also require maintenance as new fraud patterns emerge, and sophisticated operators can use many low-rate sources to stay under individual thresholds while still generating massive fraud volumes.

How Enea Fits In

Enea’s voice firewall is the enforcement point in the call path that protects operators and subscribers from fraud in real-time. It can detect fraudulent calls and then block, flag, or route them to an IVR.

  • Number intelligence. High-quality global number intelligence is essential for preventing IRSF calls. Enea collaborates with top number intelligence providers, integrating their data feeds directly into the firewall. The voice firewall also works seamlessly with existing fraud management systems.
  • Pattern recognition. Built-in detection features utilize pattern recognition and volumetric postprocessing to identify numbers associated with fraud directly within the firewall. It can either act autonomously or flag issues for a fraud team via the SOC and/or FMS.
  • Broader scope of protection. The Adaptive Voice Firewall offers broader protection. Beyond revenue fraud, it shields against Caller ID Spoofing using a zero-trust model, which is more independent and effective compared to trust-based solutions like STIR/SHAKEN.

The Adaptive Voice Firewall shares its platform with Enea’s messaging and signaling firewalls. For operators, consolidating network security into one platform simplifies operations and reduces costs.

Handbook Detecting and Countering Fraud and Revenue Leakage in Mobile Networks