"Wangiri" — Japanese for "one ring and cut" — is a mass-scale callback scam that turns curious subscribers into unwitting revenue for fraudsters running premium-rate international numbers.
An attacker dials tens of thousands of subscribers from a premium-rate international number, disconnecting after a single ring. A percentage of recipients will call back out of curiosity. Each callback is billed at premium international rates, and the attacker collects a revenue share on the termination — the same economics as IRSF, but weaponized against consumers instead of PBX systems.
Wangiri campaigns are cheap to run, hard to trace, and profitable at very small callback conversion rates. Terminating carriers see the fallout in complaints and chargebacks; originating carriers see it as a compliance and reputation problem.
Wangiri campaigns are dominated by call attempts that ring for less than two seconds before disconnect.
One source hits tens of thousands of destinations in a small window — a pattern legitimate traffic almost never shows.
Bait numbers cluster in a small set of country codes with weak termination oversight.
SipShield fingerprints wangiri fan-out patterns in real time and blocks the originating source before the campaign reaches significant subscriber volume — plus alerts on unusual callback spikes to high-risk destinations so outbound revenue leaks get caught fast.