Skip to content
Security8 min

Voice fraud - IRSF, Wangiri and PBX hacking, and how to stop them

Voice fraud costs the industry tens of billions a year, and most of it follows three well-understood patterns. What each one looks like on the wire, why it works, and the layered controls that catch it before it reaches your invoice.

DE
Dollu Engineering
Network Engineering

Fraud is a traffic pattern, not a mystery - Voice fraud has a reputation for being exotic. In practice the overwhelming majority of losses come from three schemes that have been running for two decades, and each has a recognisable shape in the CDRs. The reason they still work is that they generate traffic that looks legitimate for long enough to be billed, and that many operators and enterprises detect them monthly, when the invoice arrives, rather than in the first ten minutes. Understanding the mechanics is most of the defence.

International Revenue Share Fraud - IRSF is the largest category by value. A fraudster obtains access to premium-rate or high-cost international number ranges - often through a revenue-share arrangement with a small operator or a number-range reseller - and then generates calls to those numbers from someone else's account. The originator pays the termination rate; the fraudster and the range holder split the revenue. The traffic is generated by any means available: a compromised PBX, stolen SIP credentials, a hacked mobile subscription, or a bulk-purchased SIM. The tell-tale pattern is a sudden burst of calls to a destination the account has never called before, often a small island nation, a satellite range or a specific mobile prefix, at unusual hours, with long durations and back-to-back attempts. Losses of tens of thousands of dollars in a single weekend are routine when nothing is watching.

Wangiri - Wangiri, Japanese for "one ring and cut", is IRSF's cheaper cousin. The fraudster places millions of very short calls to consumer numbers, hanging up after one ring, from a premium-rate or high-cost international number. A percentage of recipients call back out of curiosity and are held on the line by a recording or a fake IVR while the per-minute charges accrue. From the enterprise side, Wangiri appears in two forms: your subscribers or staff calling back to unfamiliar international numbers, and, if your platform is used to generate the one-ring calls, an enormous volume of very short outbound calls with near-zero ACD. The second pattern is one of the easiest things in telecoms to detect automatically, provided someone is looking.

PBX and SIP account compromise - Most enterprise voice fraud starts with a compromised PBX or SIP account. Default or weak SIP passwords, voicemail systems that allow outbound transfer, unpatched PBX software exposed to the internet, and DISA features left enabled are the usual routes in. Attackers scan the internet continuously for SIP endpoints, and a newly exposed PBX will typically see registration attempts within hours. Once inside, they route IRSF or Wangiri traffic through the PBX, usually at night or over a weekend, and the enterprise discovers it when the carrier calls or the invoice arrives. The traffic pattern is again distinctive: outbound calls from an extension that normally makes none, to destinations the business has no relationship with, outside business hours.

Detection has to be real time - The single most important control is velocity and destination monitoring that runs continuously and acts automatically. That means per-account and per-destination thresholds on attempts per minute, concurrent calls, and spend per hour and per day; anomaly detection that compares current traffic against the account's own baseline rather than a global average; a maintained blocklist of known IRSF ranges, refreshed from industry sources; and automatic blocking or throttling when thresholds are crossed, with a human alerted afterwards rather than before. Monthly review of CDRs is not fraud detection; it is loss accounting.

Controls the enterprise should own - Lock down the PBX: change every default credential, disable DISA and external transfer unless genuinely required, restrict SIP registration to known IPs or use a VPN, patch promptly, and put the PBX behind an SBC or a SIP-aware firewall. Restrict destinations: most businesses have no need to call satellite phones, premium-rate ranges or the majority of the world's country codes, so block them by default and whitelist exceptions. Set spend limits per extension and per trunk. Review outbound call logs for after-hours activity, and set alerts. Educate staff and subscribers not to return calls to unfamiliar international numbers.

Controls the carrier should provide - Ask your voice provider what its fraud management system does automatically. It should offer configurable per-customer daily and hourly spend caps that hard-stop traffic; destination blocking that you can manage yourself; real-time alerts by email, SMS and API when your profile deviates; and a clear statement of liability when fraud traffic passes despite those controls. Carriers that terminate at wholesale scale see fraud patterns across hundreds of customers and can block a new IRSF range for everyone within minutes of first seeing it. That shared visibility is one of the real advantages of using a carrier with a large interconnect base rather than a small reseller.

When it happens anyway - Suspend the compromised trunk or account immediately, preserve the CDRs, change every credential on the affected system, and notify your carrier the same hour; many will work with you on disputed traffic if you report quickly and can show the compromise. Then do the post-mortem honestly. Almost every fraud incident we see traces back to a control that was known to be missing.

Layered, boring, effective - None of this is sophisticated. Strong credentials, restricted destinations, spend caps, real-time velocity monitoring, and a carrier that blocks known bad ranges will stop the large majority of voice fraud before it costs anything. The schemes are old; the reason they keep working is that the controls are optional and people opt out.