What Is Telecom Fraud? A Complete Guide for MNOs

For anyone new to vendor evaluation, the problem is not a shortage of solutions but the lack of a neutral explanation of what the challenges actually are. This guide covers the major telecom fraud attack types, explains how each one damages the MNO, and describes what effective detection looks like in each case.

Published:

  • Telecom Fraud

The Fraud Landscape: Why MNOs Are the Primary Target

Global losses from telecommunications fraud reached $41.82 billion in 2025, according to the latest CFCA Global Fraud Loss Survey. That represents roughly 2.5% of total industry revenue, and it compounds year on year. For an MNO, those losses are not abstract: they show up as unrecoverable interconnect settlement, inflated termination costs, subscriber churn driven by degraded call quality, and regulatory exposure that grows as jurisdictions tighten operator accountability for fraud traffic.

Telecom infrastructure sits at the center of global commerce and communication. That makes it a target unlike most industries. Fraud does not discriminate by operator size, with scammers targeting global mobile, fixed, wholesale, and virtual operators in equal measure. Smaller operators on legacy TDM infrastructure carry compounding exposure because their detection capabilities have not kept pace with the migration of fraud to IP networks.

Subscriber trust erosion is a measurable secondary impact. Fraudulent calls and texts have reduced subscriber confidence across the carrier base, with a measurable shift toward OTT messaging services as a result. The revenue loss from that shift is separate from, and additional to, the direct fraud losses.

Here is a structured breakdown of the major fraud categories affecting MNOs today, organized by attack mechanism and business impact.

The Major Fraud Types: A Technical Overview

Telecom Fraud Guide for MNOs

1. International Revenue Share Fraud (IRSF)

What it is: Fraudsters acquire premium rate numbers in high-termination-rate jurisdictions and generate artificial traffic to them using compromised PBX systems, SIM farms, or botnets. They collect a share of the termination revenue while the originating operator bears the full settlement cost. IRSF is consistently the highest-value fraud category, accounting for an estimated $6.23 billion in annual losses.

How it targets the MNO: The cost lands directly on the originating operator's interconnect settlement ledger. Because calls appear to complete normally, detection depends on recognizing abnormal traffic patterns before large volumes accumulate. The 2025 CFCA data found that 67% of carriers reported high volumes of IRSF attacks across both developed and emerging markets.

Detection approach: Real-time volume profiling against destination-specific thresholds, combined with live IPRN intelligence feeds such as the GSMA IRSF Prevention service. Static blacklists alone are insufficient because fraudsters constantly seek new routes; detection requires continuous adaptation.

2. Wangiri (One-Ring) Fraud

What it is: A variant of IRSF. Fraudsters place single-ring calls to large subscriber lists from premium-rate destinations, relying on callbacks to generate billable traffic to their premium rate numbers.

How it targets the MNO: Subscribers are the direct victims, but the operator faces interconnect settlement loss, complaint handling costs, and reputational harm. Wangiri operations can generate millions of incomplete calls in a short window, degrading call setup performance at scale.

Detection approach: Aggregate profiling of short-call volumes across sliding time windows. When a calling number exceeds short-call volume thresholds, it is added to a block list for a configurable period. Per-call rules will not catch Wangiri; the signal only becomes visible in the aggregate.

3. CLI Spoofing and Caller ID Manipulation

What it is: Fraudsters manipulate the Calling Line Identity (CLI) presented to the terminating network to disguise international calls as domestic, impersonate trusted institutions for social engineering, or obscure the true origin of fraud traffic. CLI spoofing was reported by 59% of carriers in the 2025 CFCA data.

How it targets the MNO: Lost interconnect revenue from misrouted traffic, subscriber losses when customers fall victim to impersonation calls, and regulatory exposure as jurisdictions increasingly mandate operators to prevent spoofed calls from their networks.

Detection approach: Numeration consistency checks that verify the CLI against the agreed interconnect profile for the originating carrier. Nature of Address verification at the signaling level. STIR/SHAKEN provides cryptographic CLI verification in IP networks; regional call validation schemes extend coverage to networks that have not yet deployed it.

4. SIMBox and Interconnect Bypass Fraud

What it is: Bypass operators install SIM card racks with VoIP-to-GSM gateways, receiving calls via cheap international VoIP routes and re-originating them as local mobile calls, bypassing international interconnect agreements entirely. Bypass fraud costs operators an estimated $4.73 billion annually.

How it targets the MNO: A direct interconnect revenue attack. The operator loses the settlement fees it would have earned on legitimate international-to-mobile termination. SIMBox calls also degrade network quality, presenting anomalous signaling behavior and inferior audio characteristics.

Detection approach: Test call generation to inspect whether calls arrive with expected signaling characteristics. Traffic consistency checks against carrier-agreed numeration profiles. Audio fingerprinting for calls that pass signaling inspection but carry the acoustic characteristics of VoIP-to-GSM conversion.

5. Robocalls and Voice Spam

What it is: High-volume automated calls used for telemarketing, phishing, OTP bypass, and increasingly AI-generated social engineering. Flash calls occupy a gray area: GSMA has recognized them as a legitimate OTT authentication technique, but unmonitored flash call traffic suppresses A2P SMS revenue without generating corresponding interconnect revenue.

How it targets the MNO: Subscriber experience degradation drives complaints, churn, and erosion of trust in the voice channel. Operators in many jurisdictions also face compliance obligations to prevent spam calls reaching subscribers, with associated penalties.

Detection approach: Real-time profiling of calling numbers for anomalous patterns. For flash calls specifically, correlation with A2P SMS traffic enables operators to identify OTT origination ranges and make informed policy decisions about blocking or monetization.

6. PBX Hacking and Enterprise Infrastructure Abuse

What it is: Fraudsters gain unauthorized access to enterprise PBX systems through weak credentials or unpatched VoIP vulnerabilities, then generate large volumes of calls to premium-rate destinations. Enterprise losses often reach tens or hundreds of thousands of dollars before detection.

How it targets the MNO: While the direct financial loss falls on the enterprise, the operator faces subscriber churn, reputational damage, and regulatory scrutiny for carrying fraud traffic. Customers who suffer PBX fraud events frequently attribute blame to their operator regardless of where the vulnerability originated.

Detection approach: Monitoring of parallel session counts per originating connection, since hacking events produce abnormal simultaneous outbound call volumes from a single endpoint. Real-time volume thresholds on calls to high-risk prefixes, with automated notification to the enterprise, enabling rapid containment.

7. Roaming Fraud

What it is: Fraudsters exploit the settlement credit implicit in roaming agreements, consuming high-value services before reconciliation occurs. This includes subscription fraud (activating a contract specifically to exploit roaming) and identity-based account takeover. Subscription and identity fraud account for an estimated $5.31 billion in annual losses according to CFCA.

How it targets the MNO: Losses accumulate between service consumption and settlement reconciliation. For high-value services, the gap between usage and settlement can produce significant unrecoverable losses before the fraud is identified.

Detection approach: Real-time monitoring of roaming subscriber usage against behavioral profiles, HLR queries to verify location consistency, and velocity checks that flag implausible usage patterns across geographically inconsistent locations within short time windows.

What Effective Detection Looks Like: A Framework

For an MNO evaluating fraud management capabilities, the following represent the core functional requirements for comprehensive voice fraud protection in 2026:

  • Pre-call interception vs. post-call analysis: Detection that occurs before call setup completes allows the system to terminate, reroute, or degrade fraudulent calls before any billable event occurs. Systems that analyze CDRs after the fact can identify fraud but cannot recover the revenue already lost.
  • Multi-layer detection logic: No single technique covers the full fraud surface. Effective platforms combine rule-based evaluation (for known patterns), active checks (HLR queries, callback verification, IVR-based voice CAPTCHA for robocall detection), and real-time analytics using sliding time windows (for volume-based attacks like IRSF and Wangiri that only become visible in aggregate).
  • Support for both SIP and SS7/SIGTRAN: Most MNOs operate hybrid networks. A firewall that enforces policy only on IP traffic leaves legacy TDM trunks exposed.
  • Low false positive rate: Detection without precision generates operational overhead that fraud teams cannot sustain. False positives that block legitimate calls also create subscriber complaints and potential churn, defeating the purpose of protection.
  • Configurable actions beyond binary block/allow: Operators benefit from the ability to apply partial blocking (to test new detection rules before full deployment), call degradation (to identify SIMBoxes without alerting the operator), and selective rerouting (to IVR or voicemail while preserving interconnect revenue).
  • Integration with industry intelligence feeds: Fraud destination ranges, IPRN databases, and known-bad CLI lists change continuously. A platform that can ingest external intelligence in real time from sources like the GSMA IRSF Prevention service or CFCA-shared threat data. This maintains currency that static internal databases cannot match.

Next Steps: How to Effectively Combat Telecom Fraud

To sum it up, effective telecom fraud protection platforms combine rule-based evaluation for known patterns, active checks such as HLR queries and callback verification, and real-time analytics using sliding time windows for volume-based attacks that only become visible in aggregate. Support for both SIP and SS7/SIGTRAN is a baseline requirement for any operator running a hybrid network. And detection precision matters as much as coverage: a low false positive rate is the difference between a system fraud teams trust and one they route around.

For example, Heksagon's award-winning Voice Firewall applies pre-call interception logic across SIP and SS7/SIGTRAN simultaneously, currently protecting over 600 million subscribers and blocking more than 9 million fraudulent calls per month at a 0.01% false positive rate. For operators with signaling layer exposure, our  Signaling Firewall covers SS7 and Diameter protocol abuse within the same detection and reporting environment.

For teams already assessing platform options, contacting Heksagon is the right starting point.