1. The economics: why wholesale fraud exists at all
Three conditions make the crime possible. Price gaps: the same call or message settles at wildly different rates depending on what the chain believes about its origin, destination and type. A trust chain: an international call crosses three to six networks, and none of them can fully verify what the previous one claims. And no referee: there is no central authority that can force a carrier in another jurisdiction to play straight. Combine the three and every price gap becomes a business plan. The ITU-T, in its 2024 technical report on OTT bypass, ranked bypass among the largest revenue-assurance threats operators face worldwide.
The consequence: fraud is not an incident, it is a permanent weather system. It scales with your traffic, adapts to your defences, and taxes every unmonitored corridor you own. Carriers that treat detection as a quarterly project pay the tax; carriers that treat it as a discipline collect it back.
2. The four families
Every technique you will ever encounter sorts into one of four families. Learn the families and no vendor presentation can confuse you again.
Family 1: Voice bypass — lying about the journey
The international call is converted into a cheap local one before the called operator sees it. SIM box fraud does it mechanically with banks of local SIMs; OTT bypass does it in software through apps and gateways. The operator loses the international termination rate; the fraudster pockets the spread. Fingerprints: ACD collapse, B-number repetition, SIM behaviour no subscriber produces.
Family 2: A-number manipulation — lying about the origin
Under origin-based rating, the presented origin sets the price, so the origin gets attacked. CLI refiling rewrites international A-numbers as domestic to arbitrage the rate card. Wangiri weaponises the callback itself with premium-rate bait. Spoofing and masking fake or suppress the identity to defeat validation and enable trust fraud. Fingerprints: numbering-plan mismatches, A-number clustering, no-CLI ratio spikes.
Family 3: Messaging fraud — lying about the traffic type
Grey routes carry A2P traffic over P2P-priced channels. SMS pumping (AIT) manufactures OTP volume toward ranges someone gets paid to terminate. Firewall evasion probes the policy layer for gaps. The sender pays full price for delivery that never had guarantees. Fingerprints: throughput no human produces, sender ID inconsistency, destination concentration with zero conversion.
Family 4: Billing and settlement leakage — lying about the numbers
The quietest family: interconnect invoices that drift from CDRs, Pay TV and VOD revenue share settled on distributor-reported figures, stale entitlements, mobile money agent anomalies, manipulated DLRs that report delivery that never happened. No hacker required, just aggregation at scale and nobody reconciling. Fingerprints: settlement-versus-CDR gaps, entitlement staleness, DLR provenance inconsistencies.
| Family | The lie | Steals from | Primary detection |
|---|
| Voice bypass | “This international call is local” | Called operator termination rate | CDR baselines per corridor, test calls |
| A-number manipulation | “This origin is what I say it is” | Operator rate cards, subscriber trust | Numbering-plan cross-checks, per-hop verification |
| Messaging fraud | “This A2P traffic is P2P” | Senders, brands, honest aggregators | Sender/throughput analytics, conversion tracking |
| Settlement leakage | “These are the numbers” | Everyone upstream of the report | Reconciliation, DLR provenance |
3. Detection: three methods, one discipline
Every serious programme combines targeted test calls (prove a corridor is dirty, sample almost nothing), CDR statistical analytics (cover everything, need calibrated baselines) and signalling inspection (precise where visible, usually not visible on transit). Each fails alone; together they work. Two numbers keep the discipline honest: on machine-flagged traffic, expect on the order of a third of flags to be false positives without expert review, and recalibrate thresholds quarterly because last quarter’s patterns are already aging. Machines propose, engineers confirm.
4. The prevention stack that actually works
Five layers, boring on purpose, effective in combination:
1. Per-corridor baselines. Analytics that know what normal looks like per destination, so drift surfaces in days instead of quarters.
2. Identity verification. Per-hop A-number checks, numbering-plan cross-checks, sender ID consistency, DLR provenance.
3. Your own test traffic. Auditing the routes you buy with your own calls and messages, so you learn what path they really took.
4. Commercial consequences. Evidence-backed repricing and exit for partners whose routes leak. Analytics without escalation is a museum.
5. Recalibration cadence. Quarterly threshold review against fresh patterns, because fraud adapts faster than procurement.
5. Five questions to ask any carrier or vendor
1. Where is your fraud detection output consumed? A dashboard is not a decision.
2. What was your last measured false-positive rate on fraud flagging, and who reviewed it?
3. How fast does a flagged corridor reach a human, and what is the escalation window?
4. What happens commercially when you catch a partner leaking or refiling?
5. What did you catch last quarter that a human would have missed, and the reverse?
If the answers are vague, you are not buying fraud protection. You are buying a brochure.