Telecom Fraud Taxonomy
Telecom fraud is the industry's largest ongoing operational loss. The CFCA loss survey has tracked global fraud losses in the $30–40 billion range for over a decade; the underlying attack techniques evolve, but the taxonomy is stable enough to defend against systematically. Fraud sits at the intersection of network security, revenue assurance, and law enforcement, and the same signaling primitives that enable subscriber tracking also enable most fraud vectors.
This hub aggregates everything the Ultimate Guide covers on fraud: International Revenue Share Fraud (IRSF) and its dependency on premium-number routing, Wangiri callback fraud and its variants, SIM box bypass and the CLI/CDR fingerprints operators use to detect it, PBX hacking and IP-PBX abuse, subscription and application fraud at the retail edge, CLI spoofing at the interconnect layer, A2P SMS grey routing and its impact on operator termination revenue, roaming fraud (premium-rate roaming, IRSF-via-roaming, GT scanning), and account takeover paths that lean on SIM swap and SS7-based SMS interception.
Fraud defense is layered. Real-time signaling firewalls stop the technical enablers (SS7-based interception, Diameter subscriber-data reveal, GT scanning); fraud management systems (FMS) with CDR/EDR analytics catch the fraudulent traffic patterns; commercial and contractual controls (interconnect agreements, wholesale termination rate design) remove the economic incentive. A telecom-fraud program that only invests in one layer leaves the other two open.
Frequently asked questions about telecom fraud taxonomy
What is IRSF (International Revenue Share Fraud) and how do operators stop it?
International Revenue Share Fraud (IRSF) is a fraud scheme where criminals generate high volumes of calls to premium international numbers whose revenue is shared with them by the terminating carrier. It typically abuses hacked PBXs, compromised SIMs, or subscription fraud to drive traffic. Defenses include real-time call-pattern analytics, destination allow/deny lists, velocity limits on new subscribers, wholesale carrier due diligence, and industry data sharing (e.g. CFCA feeds).
What is a Wangiri fraud scam?
Wangiri (Japanese for "one ring and cut") is a fraud where scammers place a very short call from a premium international number, hoping the recipient calls back and incurs charges that route revenue to the fraudsters. It is a variant of IRSF and is countered with the same techniques: destination blocking, callback pattern detection, subscriber education, and coordination between operators via GSMA and CFCA channels.
What is a SIM box (interconnect bypass fraud) and why is it a problem?
A SIM box is a device holding many local SIM cards that terminates inbound international VoIP traffic as local mobile calls, bypassing the legitimate international interconnect and its termination fees. It causes revenue loss for the operator, degraded call quality, incorrect CLI presentation, and often coincides with subscription fraud on the SIMs used. Detection relies on test-call generation, traffic analytics on CDRs (unusual call patterns, high outbound-only SIMs), and radio-side fingerprinting.
How big are annual telecom fraud losses globally?
The Communications Fraud Control Association (CFCA) survey estimates industry fraud losses in the tens of billions of USD per year, with IRSF, subscription fraud, PBX toll fraud and Wangiri consistently in the top categories. Loss estimates vary widely by methodology (invoiced-but-unpaid vs. termination-fee leakage vs. downstream fraud enabled), and losses continue to shift toward A2P SMS bypass, flash-call abuse, and OTT bypass as call volumes migrate. Individual operator exposure depends heavily on interconnect footprint and MVNO tenants.
What are fraud management systems (FMS) in telecom?
Fraud management systems analyze CDRs, signaling data, and subscriber behavior patterns to detect revenue fraud such as International Revenue Share Fraud (IRSF), Wangiri (one-ring) fraud, SIM box fraud, and subscription fraud. Modern FMS solutions use machine learning to identify emerging fraud patterns and can trigger automated responses like call blocking or subscriber alerts.
Related glossary terms
- Revenue Share Fraud International Revenue Share Fraud (IRSF Model)
- IRSF International Revenue Share Fraud
- Toll Bypass
- Toll Fraud
- PBX Dial-Through Fraud
- Subscription Fraud
- BGCF Breakout Gateway Control Function
- Wangiri 2.0 Wangiri 2.0 (Web-Initiated Callback Fraud)
- PBX Toll Fraud PBX Hacking / Toll Fraud
- Artificial Traffic Inflation Fraud Context
Related comparisons
Compliance crosswalks
More on Telecom Fraud
Browse all topic hubs, the Ultimate Guide to Mobile Network Security and the TelcoSec Glossary.