- Why fraud is a wholesale problem specifically
- The fraud types that matter
- International revenue share fraud (IRSF)
- Wangiri
- Traffic pumping and access stimulation
- PBX and credential compromise
- Subscription and identity fraud
- How fraud reaches your network
- Controls that actually work
- Restrict destinations by default
- Enforce concurrency and velocity ceilings
- Use IP authentication where you can
- Monitor CDRs for anomalies, not just totals
- Set hard credit and balance ceilings
- Read your failure codes
- Make out-of-hours detection somebody's job
- When you are mid-incident
- Frequently Asked Questions
- Who is liable for fraudulent traffic on a wholesale account?
- How quickly can voice fraud generate a significant bill?
- Does STIR/SHAKEN prevent fraud?
- Should I block all international traffic by default?
- Is fraud risk a reason to avoid wholesale voice?
- Getting the controls right from the start
Voice fraud is the risk most new wholesale buyers underestimate and most experienced ones have been burned by at least once. Unlike a data breach, telecom fraud converts directly into money within hours, and the liability usually lands on whoever's credentials were used — not on the person who used them. A single compromised customer PBX over a long weekend can generate a bill large enough to erase a quarter of margin.
This article covers the fraud patterns that specifically target wholesale voice, how they get into a network, and the controls that actually work. It is written for people operating a switch and carrying commercial risk, not as a general security overview.
Why fraud is a wholesale problem specifically
Retail customers are largely insulated. Their provider absorbs fraud risk as a cost of doing business and caps exposure with bundled plans. Wholesale is different in three ways:
- You are billed for usage, not seats. There is no natural ceiling on a per-minute product. Fraudulent traffic is billable traffic.
- You aggregate other people's risk. Every customer PBX you connect is an attack surface you do not control.
- Fraud is fast. Automated dialers can generate enormous volumes of high-cost international traffic in the time it takes to notice something looks unusual.
The uncomfortable structural reality: traffic that leaves your switch and terminates on a foreign network has been carried by real carriers who expect to be paid. "It was fraud" is rarely a successful basis for non-payment. Your protection is prevention and early detection, not dispute.
The fraud types that matter
International revenue share fraud (IRSF)
The dominant financial threat in wholesale voice. Fraudsters obtain number ranges in destinations with high termination costs, then generate traffic to them from compromised systems. The revenue from terminating those calls is shared back to the fraudster. Because the payout scales with minutes, IRSF campaigns are designed for volume — long-duration, high-concurrency traffic to expensive destinations, usually starting outside business hours.
Characteristic signals: sudden traffic to destinations a customer has never called, unusually long call durations, high concurrency from a single endpoint, and a start time chosen to maximise the window before anyone notices.
Wangiri
Japanese for "one ring and cut." The fraudster places brief calls that hang up before answer, leaving a missed call from an international number. Victims call back and are held on an expensive premium line. For a wholesale operator this shows up as an inbound origination problem and a reputational one — your DIDs may be used to receive callbacks, or your customers may be generating expensive outbound callbacks.
Traffic pumping and access stimulation
A domestic variant where traffic is artificially inflated to destinations that generate access charges, historically to rural US rate centres with high terminating access rates. It presents as implausible call volumes to a narrow set of geographic destinations, often with long durations and low answer variability.
PBX and credential compromise
This is the delivery mechanism for most of the above. Weak SIP registration credentials, exposed SIP ports, default extension passwords and unpatched PBXs are found by automated scanning within hours of exposure. Once registered, the attacker has legitimate credentials on your platform, so the traffic looks authorised.
Subscription and identity fraud
A fraudster signs up as a customer with no intention of paying, generates maximum billable traffic and disappears. Prepaid models and credit limits exist largely to contain this.
How fraud reaches your network
- Exposed SIP endpoints. Any SIP service reachable from the open internet is being scanned continuously.
- Weak or reused credentials. Registration passwords that match extension numbers remain distressingly common.
- Unrestricted dial plans. Customers who can dial any destination in the world by default, whether or not they ever need to.
- Compromised customer premises equipment. Unpatched PBXs and misconfigured SBCs.
- Insider misuse at a customer site — less common but harder to detect.
Note that NAT and firewall middleboxes can obscure diagnosis of both fraud and ordinary faults. If you are chasing strange signalling behaviour, rule out network-layer interference first — our SIP ALG guidance covers the most common culprit.
Controls that actually work
Restrict destinations by default
The single highest-value control. Most customers never legitimately call most of the world. Default new accounts to domestic and a small set of required international destinations, and require an explicit request to open high-risk ranges. Fraud economics collapse when the expensive destinations are unreachable.
Enforce concurrency and velocity ceilings
Cap simultaneous calls and call attempt rate per customer at a level slightly above their legitimate peak. A ten-seat customer generating fifty concurrent international calls is not having a busy day. Ceilings turn an unbounded loss into a bounded one.
Use IP authentication where you can
Static IP authentication is materially harder to abuse than registration credentials, because stealing a password is easier than stealing a network location. Where customers have fixed addresses, prefer it. Where they do not, enforce strong unique credentials and monitor registration origin.
Monitor CDRs for anomalies, not just totals
Spend thresholds alone alert too late. Watch for pattern breaks: first-ever traffic to a destination, out-of-hours volume, duration distributions that shift suddenly, concurrency spikes, and repeated identical destinations. Alert on the pattern change, not the invoice.
Set hard credit and balance ceilings
Prepaid balances and enforced credit limits are blunt but effective — they define your maximum loss in advance. Make sure you know exactly what happens to live traffic when a ceiling is reached, and that the behaviour is enforced automatically rather than by someone reading an email.
Read your failure codes
Fraud attempts often generate distinctive rejection patterns before they succeed. High volumes of authentication failures or unusual rejection codes are early warning. Our SIP response code reference explains what specific codes indicate.
Make out-of-hours detection somebody's job
Fraud is deliberately timed for when nobody is watching. Automated alerting that reaches a human on a Friday night is worth more than a sophisticated dashboard nobody opens until Monday.
When you are mid-incident
Speed beats diagnosis. A workable order of operations:
- Stop the traffic. Suspend the affected account or block the destination range. Do not wait to establish root cause — every minute is billable.
- Preserve evidence. Export CDRs and SIP traces for the window before anything rotates out of retention.
- Notify your carrier immediately. Early notification is the only realistic path to any commercial discussion, and it may allow blocking further upstream.
- Rotate credentials for the affected account and anything sharing them.
- Establish the entry point before restoring service, or you will simply be defrauded again.
- Tighten the control that failed rather than only cleaning up the incident.
Frequently Asked Questions
Who is liable for fraudulent traffic on a wholesale account?
In practice, the account holder whose credentials generated the traffic. Calls that terminated on real networks incurred real costs, so upstream carriers expect payment regardless of authorisation. Some providers will engage commercially on egregious cases, particularly where fraud was reported quickly, but you should plan on the assumption that you are liable and build controls accordingly rather than relying on goodwill.
How quickly can voice fraud generate a significant bill?
Quickly enough that detection windows matter more than anything else. High-concurrency automated dialing to expensive destinations can run continuously and unattended, which is why attacks are typically launched at the start of a weekend or holiday. This is the argument for hard concurrency ceilings — they cap exposure without requiring anyone to be awake.
Does STIR/SHAKEN prevent fraud?
No, and conflating the two is a common mistake. STIR/SHAKEN authenticates the right to use a calling number, which addresses caller ID spoofing and illegal robocalling. It does nothing about a compromised PBX dialing expensive international destinations with entirely legitimate caller ID. You need both. Our attestation guide explains what it does and does not cover.
Should I block all international traffic by default?
Blocking all of it is usually too blunt and generates support friction. The effective approach is a default-deny posture on high-risk and high-cost ranges, with domestic and commonly used destinations open, and a simple documented process for customers to request additional destinations. This preserves usability while removing the destinations fraud depends on.
Is fraud risk a reason to avoid wholesale voice?
No — it is a reason to operate it properly. Fraud is a known, well-understood category of risk with well-understood controls, in the same way card fraud is a manageable cost of running an e-commerce business. Operators who set destination restrictions, concurrency ceilings and anomaly alerting from day one rarely suffer serious losses.
Getting the controls right from the start
Fraud controls are far easier to implement at onboarding than to retrofit after an incident. If you are building or reviewing a wholesale voice operation, our wholesale VoIP termination and origination service and the wholesale technical documentation library cover the authentication, capacity and diagnostic tooling available to partners. You can also read about our wider security and compliance posture, or talk to our team about the controls appropriate to your traffic profile.
Ready to transform your business communications?
Join thousands of enterprises trusting VirPhone for reliable cloud communication.
Ready to upgrade your business communications?
Explore our enterprise solutions designed for scale and reliability.
