Solutions / Route Integrity & Fraud

OTT Bypass Detection

Fraudsters redirect international call legs into OTT apps (WhatsApp, Skype, Viber) to skim the termination spread. Calls appear to terminate on your network but bypass the international settlement. We detect it from the call records.

The scheme

OTT bypass is the rerouting of an international call into an over-the-top app such as WhatsApp or Viber, so it terminates as cheap local data traffic instead of following the international settlement path. The called operator loses the international termination rate while an intermediary captures the difference. The ITU-T flagged it as one of the largest revenue-assurance threats to operators in its 2024 technical report on OTT bypass.

Where the international call leg disappears.

Traditional SIM box fraud terminates international calls as local via GSM gateways. OTT bypass is the next-generation variant: fraudsters route the international leg into an OTT app, the OTT terminates the call as data on the destination MNO. International settlement is never raised. The MNO sees local data traffic, not an international call.

Short call signatures

Short call signatures

OTT-originated calls have a distinctive signature, short durations, clustered A-numbers, repeated B-number patterns. We flag them within minutes.

CLI inconsistency

CLI inconsistency

OTT-originated calls often present a domestic CLI on a call that should be international. We cross-check CLI against expected routing.

Behavioural baselines

Behavioural baselines

Per-corridor baselines on ACD, ASR and CLI presentation. OTT bypass shows up as deviation from the corridor’s normal traffic shape.

How it works

Detection in the CDR stream, not in firewall rules.

OTT bypass is hard to catch with firewall rules, the traffic looks like OTT data, not international voice. The detection happens in the CDR stream, comparing observed behaviour against per-corridor baselines.

01

CDR ingestion

Real-time ingestion of call records. We correlate the international leg, the OTT leg and the terminating leg, and flag the gap.

02

Baseline per corridor

Each corridor has its own normal. ACD below two minutes on a corridor where the baseline is six, with a cluster of identical A-numbers, is the OTT bypass signature.

03

Human review before block

Automatic rules throw false positives, typically around 30% of flagged traffic. Our analysts review before the route is hard-blocked, so legitimate OTT calls are not collateral damage.

04

Quarterly recalibration

OTT bypass patterns shift as fraudsters adapt. We re-baseline every quarter and ad-hoc when an anomaly persists.

Why this matters

Because the OTT layer is not going away.

OTT voice traffic overtook international TDM in volume years ago. Some of it is legitimate OTT termination. Some of it is bypass dressed up as OTT. The job is to tell the difference.

The cost

Margin spread

OTT bypass does not appear on the fraud loss line of the P&L. It appears as revenue you never saw, calls that should have generated international settlement but instead rode OTT and paid you nothing.

You cannot reconcile what was never billed.

Field note

Fraud teams that focused for years on SIM box detection now spend an increasing share of their time on OTT bypass. The mechanics are different; the loss is the same, termination revenue that should have been collected and was not.

We detect both.

Detection methods, compared.

Every serious OTT bypass programme combines three methods, because each one fails alone. Test calls prove a corridor is dirty but sample almost nothing. CDR analytics cover everything but need calibrated baselines. Signalling inspection is precise where it is visible, and on most transit hops it is not.

MethodWhat it catchesLatencyCoverageWeakness
Targeted test callsProves active bypass on a corridorDaysOne route at a timeTiny sample, quickly gamed once detected
CDR statistical analyticsSystemic bypass, drift, corridor patternsHours to daysAll trafficNeeds baselines; roughly a third of flags are false positives without expert review
Signalling inspectionRe-origination points, header anomaliesReal timeWhere signalling is visibleNot visible on most transit hops

What it costs: the ITU-T technical report on OTT bypass published in 2024 ranks it among the largest revenue-assurance threats to operators worldwide, and CFCA industry estimates put total telecom fraud losses in the tens of billions of dollars per year. Leakage per operator scales with corridor mix and detection maturity, which is exactly what this observatory measures.

Our operating rule has not changed since day one: machines propose, engineers confirm, thresholds recalibrate quarterly. Detection without escalation is a museum.

Next

Suspect OTT bypass on your routes?

Send us 48 hours of CDRs. We will flag the calls that look like OTT termination dressed up as direct.

Frequently asked questions

What is OTT bypass?

OTT bypass is the rerouting of an international call into an over-the-top app, such as WhatsApp, Viber or Skype, so it terminates as domestic data traffic. The caller dials an international number, but the called operator never sees an international call, so it never bills the international settlement rate.

How does OTT bypass differ from SIM box fraud?

SIM box fraud terminates calls through banks of local SIM cards. OTT bypass terminates them through apps on ordinary handsets or gateways. Both convert international calls into cheap local ones; the footprint they leave in the CDR stream is different.

What CDR signatures indicate OTT bypass?

Classic signatures: abnormally short average call duration, high repetition of the same B-numbers, uniformity of A-numbers, sudden ACD collapse on specific corridors, and traffic that should be international arriving as on-net or national.

How is OTT bypass detected?

Three complementary methods: targeted test calls into suspect corridors, statistical CDR analytics against per-corridor baselines, and signalling inspection where available. Machine flagging alone produces roughly a third of false positives in flagged traffic, so expert human review remains part of the loop.

What does OTT bypass cost operators?

The CFCA estimates global telecom fraud losses in the tens of billions of dollars per year, with bypass among the top categories. The exact leakage per operator depends on corridor mix and detection maturity, which is what our observatory measures.