IRSF Fraud

    IRSF Fraud — International Revenue Share Fraud

    IRSF is the single most expensive form of telecom fraud. Attackers hijack a PBX, softswitch, or SIP trunk and pump traffic to premium international destinations they secretly own — leaving the carrier or enterprise with a six-figure invoice within hours.

    How IRSF Works

    A fraudster leases a block of premium-rate international numbers from a carrier in a jurisdiction with weak oversight. That carrier pays the fraudster a share of the termination revenue for every minute delivered to those numbers. The fraudster then compromises a PBX, SIP account, or softswitch and generates as much traffic as possible to those numbers — often overnight, over a weekend, or during a holiday when nobody is watching.

    By the time the enterprise or carrier notices, the loss can be five or six figures. Because the premium carrier is legitimate on paper, chargebacks are extremely difficult.

    Why It's Hard to Stop

    Fast Onset

    Attacks can drain $50K+ in a single overnight window before manual review kicks in.

    Rotating Destinations

    IRSF number blocks change constantly. Static blocklists go stale within days.

    No Chargebacks

    The premium carrier is nominally legitimate, so recovering the money after the fact is almost impossible.

    How SipShield Blocks IRSF

    SipShield scores every outbound call in real time against a continuously refreshed IRSF destination feed and a behavioral baseline for each customer. Abnormal spikes to high-risk country codes are rate-limited or blocked in the same second they occur — not the next morning.