Technical Deep Dives
A torn settlement report reveals hidden fraud underneath: carriers must stop IRSF before settlement to avoid this exposure.

Stopping IRSF Before Settlement: Real-Time Fraud Detection for Wholesale Carriers

A settlement report lands on a wholesale carrier’s desk in early October, and one line stands out. A small island nation—rarely more than a rounding error in the traffic mix—suddenly accounts for tens of thousands of terminating minutes. No alarm went off when those calls entered the network. Nothing blocked them at setup. By the time anyone noticed, the invoice was already real.

This is a familiar shape for wholesale carriers and interconnect providers moving international voice traffic. Most discussion of Artificially Inflated Traffic (AIT) treats it as a messaging problem, tied to SMS pumping and A2P throughput. On the voice side, the same economics show up under a different name: International Revenue Share Fraud (IRSF). Carriers who wait for settlement to catch it are always working from behind.

Stopping IRSF means validating traffic at the point where it enters the network, before it ever reaches a bill. That’s the shift this piece walks through, and where platforms like 1Route’s EDGE and FINIS come in.

The AIT Content Gap: Why Voice-Side Fraud Gets Overlooked

Search for guidance on Artificially Inflated Traffic and nearly everything points to SMS. Industry coverage treats AIT as an A2P messaging issue: SMS pumping, OTP pumping, sender ID abuse. That focus makes sense given how visible messaging fraud has become, but it leaves a gap for anyone dealing with the same pattern on voice.

The mechanics translate almost directly. A fraudster generates artificial volume toward premium or high-tariff destinations, splits the revenue with a partner at the far end, and profits from traffic that looks legitimate at the signaling level. On the messaging side, that’s AIT. On the voice side, it’s IRSF, and it rarely gets the same attention.

For a wholesale carrier watching interconnect revenue disappear into a handful of unfamiliar destinations, that gap in the conversation is the whole problem.

A laptop displays search results for SMS fraud and OTP pumping, while a smartphone nearby shows an unanswered incoming call.

What International Revenue Share Fraud Actually Looks Like

IRSF starts with access to an international premium number range, sometimes rented, sometimes obtained through a compromised PBX or hijacked SIP trunk. A fraudster drives call volume toward that range from anywhere it can be sourced, and the operator behind the number shares the inflated termination revenue.

From a signaling standpoint, none of this looks unusual. Call setup completes normally. The fraud lives in the pattern: destination clustering toward unfamiliar high-tariff countries, call durations that run longer than a genuine conversation would, and volume that spikes from a single source without a matching change in demand.

One practical signal carriers can watch for is conversion behavior. Healthy call and OTP flows typically convert in the 70 to 90 percent range. Traffic tied to IRSF or AIT often converts in the single digits, since the calls are built to generate duration and volume regardless of whether anyone answers.

Why Settlement Discovery is Already Too Late

Most fraud detection in telecom still happens after the fact: a Call Detail Record review at the end of the billing cycle, a settlement reconciliation that flags an unusual payout, an interconnect partner disputing a bill nobody expected. By the time any of that surfaces, the calls have already completed and the revenue-share obligation is already owed.

That lag is where carrier settlement risk actually lives. A fraud pattern that runs undetected for even a few weeks can generate a termination bill the carrier is contractually obligated to pay, regardless of whether the traffic was ever legitimate. Disputing it after settlement is possible, but slow, and recovery is far from guaranteed.

Global telecom fraud losses reached an estimated $38.95 billion in a single year, according to the Communications Fraud Control Association, representing roughly 2.5% of total industry revenue. IRSF remains one of the fraud types most closely tied to that total, and none of it gets easier to recover once a call has already been billed.

Is Artificially Inflated Traffic the Same as IRSF?

Not exactly. AIT functions as an umbrella term for artificially generated traffic volume designed to exploit revenue-sharing arrangements. IRSF is the voice-side expression of that same pattern: calls driven toward international premium numbers to generate shared termination revenue.

Access stimulation, sometimes called traffic pumping, is a separate and specifically regulatory category. The Federal Communications Commission defines it as an arrangement between a local exchange carrier with high switched-access rates and a high-volume calling service, evaluated against defined inbound-to-outbound traffic ratios. It governs domestic compensation disputes between carriers, not the injection of fraudulent international traffic.

The confusion is understandable. Both involve traffic volume disproportionate to normal calling patterns, and both eventually surface as unexpected charges. Access stimulation is a compliance and billing framework aimed at U.S. local exchange carriers.

IRSF is a fraud pattern that can originate anywhere in the world, exploiting gaps in call validation instead of gaps in tariff structure. Confusing the two makes it harder to apply the right defense to either.

Infographic titled 'Before the Bill Exists,' showing five steps to stop IRSF before a call becomes a billable event.

Real-Time Detection at the Network Edge

Stopping IRSF before it reaches settlement means moving detection to the point where calls enter the network, ahead of the point where they get billed. That shift depends on two layers working together.

At the network boundary, a Session Border Controller can enforce policy on inbound traffic in real time: rate limits per peer, destination allow and deny lists, and rejection of calls that violate expected patterns before setup completes. This is inbound traffic validation in its most direct form, and it catches obvious violations quickly.

The harder cases require deeper visibility. SIP signaling inspection, alongside monitoring of SS7 and Diameter signaling for legacy and mixed networks, lets a system evaluate call setup behavior, destination clustering, and duration patterns as they happen, ahead of when a CDR gets generated.

Real-time call blocking at this stage does not require perfect certainty. It requires enough signal to reject or flag a call before it becomes a completed, billable event.

How 1Route’s EDGE and FINIS Validate Traffic at the Network Ingress

This is the architecture problem 1Route’s platform is built to solve. EDGE Computing Solution sits at network ingress, validating STIR/SHAKEN attestation and inbound traffic in real time to help block fraudulent calls during setup. Meanwhile, the FINIS Platform operates inside the core SS7 and SIP signaling layer, functioning as a firewall that detects patterns associated with SIM boxing, Wangiri, and IRSF as they occur.

Together, these two layers catch fraud where the call happens, ahead of settlement. A third layer, On-SIM protection, extends that same approach to the subscriber’s device.

This is the same pattern discussed in 1Route’s breakdown of the telecom fraud supply chain, where fraud moves through specialized infrastructure and routing before it ever reaches a subscriber. It’s also related to how certain country codes can mask the same kind of high-tariff, high-volume traffic IRSF depends on.

None of this eliminates fraud entirely, and no carrier should expect it to. What it changes is when fraud gets caught, and how much financial exposure a carrier absorbs before that happens. For carriers evaluating their current fraud prevention approach, the deciding factor is usually how early in the call path validation happens.

A network engineer reviews SIP, SS7, and Diameter signaling call flows on a monitor to inspect real-time call setup behavior.

Frequently Asked Questions

How does a Session Border Controller stop IRSF in real time?

A Session Border Controller sits at the network boundary and can enforce policy on every inbound call before it connects, including rate limits, destination restrictions, and rejection of traffic that doesn’t match expected patterns. It’s often paired with deeper signaling inspection for fraud a simple policy rule wouldn’t catch.

What’s the difference between SIP signaling inspection and SS7 monitoring?

SIP signaling inspection applies to IP-based voice networks, while SS7 monitoring covers the legacy signaling protocol still used across much of the world’s TDM infrastructure. Carriers running both network types generally need visibility into each protocol separately, since fraud patterns can look different depending on which one a call travels through.

Can carriers recover revenue lost to IRSF after settlement?

Recovery after settlement is possible through dispute processes with interconnect partners, but it is slow, and outcomes vary depending on contractual terms and the strength of the traffic evidence. Preventing the fraud before the call is billed avoids the dispute altogether.


The line on that settlement report doesn’t have to be a surprise. Fraud that hides inside normal-looking call patterns is detectable earlier than most carriers currently catch it. In one 2023 study, an IRSF detection model running directly at the network edge outperformed the telecom provider’s existing centralized system by nearly five percentage points, without ever sending raw call data back to a central location.

That’s a small number on paper. Applied across a month of interconnect traffic, it’s the difference between catching a fraudulent route in its first hours and reading about it in an invoice. Wholesale carriers ready to move detection earlier in the call path can get in touch with 1Route’s team to talk through where EDGE and FINIS fit into their network.

Author

Jeffrey Ross

Jeffrey Ross is a seasoned leader with over two decades of experience across international finance and telecommunications. As the founder and CEO of 1Route Group, he is driven by a simple but powerful belief: that people everywhere deserve to trust the communications they receive. That conviction is the foundation everything at 1Route is built on. Jeff leads with purpose, surrounding himself with exceptional people and pushing toward a future where global communication is safer, more reliable, and more human. He believes that beneath all our differences, we have far more in common than we realize, and that great things happen when we dare to act on that belief.