Every fraud story in wholesale voice is a story about two numbers. The A-number and the B-number are the oldest identifiers in telephony, and nearly every revenue attack in this industry is an attack on one of them. If you buy, sell or supervise international voice, this anatomy is the foundation everything else stands on.
The A-number and the B-number
The A-number is the calling party: the origin, the identity of who initiated the call. The B-number is the called party: the destination. Between them sits the call chain: the originating network, zero or more intermediate carriers, and the terminating operator who delivers the call and bills for it.
That chain is where the money lives. Termination rates are set by destination (the B-number) and, increasingly, by origin (the A-number) under origin-based rating schemes. Whoever controls what the chain believes about these two numbers controls what the call costs.
Attack one: lying about the A-number
Three distinct frauds manipulate the calling number, and confusing them costs money:
CLI refiling rewrites an international A-number into a domestic one, so the call settles at domestic rates instead of international. It is pure arbitrage, performed at scale by intermediaries in the chain. Detection: numbering-plan cross-checks, per-hop A-number integrity, A-number clustering against per-corridor baselines.
CLI spoofing presents a false A-number to impersonate someone: a bank, a government line, a local subscriber. The goal is trust, not rating. It enables vishing and smishing against the called party, and it drags your ranges’ reputation down with it.
CLI masking suppresses or degrades the calling identity entirely, so the terminating network cannot validate origin at all. Masking defeats numbering-plan checks and often rides along with refiled traffic.
We cover the full comparison, with a detection-signal table, in the CLI Refiling Detection Observatory.
Attack two: lying about the journey
The B-number is rarely forged; it is the product. What gets attacked is the path to it. OTT bypass and SIM box fraud both convert an international call to a B-number into a cheap local one: the caller dials international, the chain re-origates the call locally, and the terminating operator sees a domestic call to the same subscriber. The B-number did not change; its context did. That is why bypass detection lives in traffic statistics, ACD collapse and B-number repetition patterns, not in the numbers themselves. The OTT bypass observatory covers the methodology.
The metrics that watch the story
Once you see the call as a story about two numbers, the classic wholesale metrics read like a security log:
- ASR (Answer Seizure Ratio): how often calls to a B-number range actually answer. Collapsing ASR on a corridor means something changed in the chain.
- ACD (Average Call Duration): bypass and refiled traffic run short, because the callers are redialling, not talking.
- PDD (Post-Dial Delay): unusual delays expose detours and re-origination hops.
- NER (Network Efficiency Ratio): how much of what you handed into the chain arrived at the B-number as intended.
Why this matters if you are not a fraud analyst
Because you are paying for it either way. Every A-number lie is a margin someone extracted from your settlement. Every re-originated call to a B-number is termination revenue you invoiced but never received. The anatomy is simple; the discipline is watching it continuously, corridor by corridor, against baselines that know what normal looks like.
That is the daily work of our observatories. See them here, or talk to the team about your own corridors.