security
How SIPSTACK Detects and Blocks Telecom Fraud in Real Time
Telecom fraud isn’t a rare problem that happens to other businesses. The Communications Fraud Control Association (CFCA) estimates global telecom fraud losses exceed $28 billion annually, and a significant portion of that targets business phone systems — often without the victims knowing until a phone bill arrives with five figures of unexpected charges.
SIPSTACK’s approach to fraud prevention is built on the same technology that powers its STIR/SHAKEN implementation and caller risk scoring: real-time analysis of call patterns, network behavior, and known threat intelligence.
The Most Common Telecom Fraud Types
Section titled “The Most Common Telecom Fraud Types”International Revenue Share Fraud (IRSF)
The most financially damaging fraud type. Attackers compromise a business PBX or SIP account and generate high volumes of calls to international premium-rate numbers. The attacker receives a revenue share from the premium-rate number operator. A single weekend of IRSF can generate $50,000–$200,000 in charges against the victim’s account.
Wangiri (One-Ring) Fraud
Automated systems call a number and hang up after one ring, hoping the recipient calls back. The callback is charged at premium rates. For businesses, this appears as a pattern of short inbound calls from international numbers.
SIM Swapping and Account Takeover
Attackers socially engineer a carrier into transferring a victim’s phone number to a SIM they control. With the number in hand, they bypass SMS-based two-factor authentication and gain access to accounts that use that number for recovery.
CLI Spoofing
Attackers falsify caller ID to impersonate trusted entities — banks, government agencies, business partners. For businesses making outbound calls, spoofing of their numbers by attackers can damage their caller reputation and trigger STIR/SHAKEN downgrades.
How Real-Time Detection Works
Section titled “How Real-Time Detection Works”Behavioral anomaly detection. SIPSTACK’s platform continuously monitors call patterns for each customer account. Baselines are established from normal activity: typical call volume, geographic distribution of calls, time-of-day patterns, average duration. When behavior deviates significantly from baseline — a spike in international calls at unusual hours, for example — the system flags it for automated or manual review.
Risk scoring on every call. Every inbound and outbound call is scored against SIPSTACK’s risk database, which includes:
- Known fraudulent number ranges (used in IRSF schemes)
- Numbers flagged by the global telecom fraud community
- Robocall source signatures
- STIR/SHAKEN attestation levels
Velocity analysis. IRSF attacks generate calls rapidly — sometimes hundreds per hour. Velocity limits that trigger automatic holds when unusual call volumes occur protect customers from runaway charges before the attack completes.
Geographic restriction enforcement. SIPSTACK allows customers to restrict calling to specific countries or regions. When a call is attempted to a blocked destination, it’s rejected at the platform level and logged for review.
Automatic Blocking vs. Alert-Based Response
Section titled “Automatic Blocking vs. Alert-Based Response”Some fraud types warrant automatic blocking — calls to known fraudulent international number ranges, for example, should be stopped without waiting for human review. Others generate alerts that the security team or customer reviews before action.
SIPSTACK’s fraud prevention system is configurable: businesses can define their own risk thresholds, add custom block lists, and choose between automatic action and alert-based review for different risk levels.
What Businesses Can Do
Section titled “What Businesses Can Do”Enable geographic call restrictions. If your business doesn’t make international calls, block international dialing entirely. If you do call internationally, whitelist the specific countries you actually call.
Set concurrent call limits. Restrict the maximum number of calls your account can have in progress simultaneously. A legitimate business rarely needs more than a defined maximum; an IRSF attack may attempt hundreds.
Review CDRs regularly. Weekly review of call detail records catches unusual patterns before they become expensive. Look for calls to unfamiliar international prefixes, very short calls to international numbers, and calls outside business hours.
Enable real-time alerts. Get notified immediately when your call volume, international spending, or anomaly score crosses a threshold. Fast detection dramatically limits financial exposure.
Telecom fraud is an arms race. SIPSTACK’s fraud prevention systems are updated continuously as new attack patterns emerge — protecting customers from threats that haven’t been invented yet.