Vai al contenuto principale
Torna al wiki
Fraud & Scams

What Is Toll Fraud?

Ultimo aggiornamento il 21 luglio 2026

Toll fraud is telecommunications fraud in which attackers generate calls or text messages to premium-rate or revenue-share numbers they control, pocketing a cut of the connection fees the victim pays. The classic form — international revenue share fraud (IRSF) — hijacks a company's phone system and pumps traffic to expensive international number ranges; industry bodies consistently rank it among the costliest fraud types in telecom, with global losses measured in billions annually. The modern, web-facing form needs no hacked phone system at all: it abuses any application feature that places calls or sends texts on request — above all, phone-based verification.

The revenue-share engine

The scheme works because of how international call revenue is settled. Premium and certain international number ranges carry elevated termination fees, split along the chain of carriers that route the call — and number resellers openly lease such ranges, paying the leaseholder per minute or per message delivered. An attacker who leases numbers, then causes someone else's systems to call or text them, has built a money pump: the victim pays the telecom bill, the carriers take their shares, and the attacker collects the rest. Traffic is typically routed at night and across many numbers to stay under alerting thresholds, and the fraud is usually discovered the way all billing fraud is discovered — as a horrifying invoice.

The web-facing variant

For online services, the exposed surface is any endpoint that converts a form submission into telecom spend: phone verification calls, voice OTP delivery, SMS-based two-factor codes, "call me" support widgets. Bots submit attacker-controlled premium numbers to these flows at volume — a voice-call sibling of SMS pumping, which does the same through text-message endpoints. The victim's bill arrives from their communications provider, not their carrier, and cloud telephony pricing makes the damage fast: thousands of automated verification calls to high-rate destinations can consume a startup's messaging budget over a weekend. The attack requires no compromise of anything — every request uses the service exactly as designed, which is what makes it an API abuse problem rather than an intrusion.

Shutting off the pump

Defense is a spend-control problem. Destination controls do the heavy lifting: block or require explicit allow-listing of premium ranges and high-risk country codes, and cap per-number and per-account verification attempts with rate limiting. Monitoring should alert on cost anomalies, not just request counts, because the whole scheme lives in the gap between the two. And since the pump only pays when it can run at machine volume, verifying a human before the telephony fires — the role of CaptchaFox in front of phone-verification and OTP endpoints — removes the automation that makes leased numbers profitable. A verification flow that only calls numbers a person actually typed is a flow no revenue-share operator can farm.

Informazioni su CaptchaFox

CaptchaFox è una soluzione conforme al GDPR con sede in Germania che protegge siti web e applicazioni da abusi automatizzati, come bot e spam. Il suo approccio distintivo e multilivello utilizza segnali di rischio e sfide crittografiche per facilitare un processo di verifica robusto. CaptchaFox consente ai clienti di essere operativi in pochi minuti, non richiede gestione continua e offre alle aziende una protezione duratura.

Per saperne di più su CaptchaFox, contattaci o inizia a integrare la nostra soluzione con una prova gratuita.

Termini correlati

What Is Triangulation Fraud?

Triangulation fraud uses a fake storefront to take real customers' money, then fulfills their orders from a legitimate shop using stolen cards.

Continua a leggere
What Is a Data Controller vs. a Data Processor?

Under the GDPR, the controller decides why and how personal data is processed while the processor acts on its instructions — a split that assigns liability.

Continua a leggere
What Is a Web Cookie?

A web cookie is a small piece of data a website stores in the browser to remember state — the mechanism behind sessions, preferences, and tracking.

Continua a leggere
What Is Data Minimization?

Data minimization is the GDPR principle that personal data must be limited to what a stated purpose actually requires — collect less, keep it shorter.

Continua a leggere

Combatti i bot e proteggi i dati dei tuoi utenti.

Non dare ai truffatori e agli spammer alcuna possibilità e proteggi il tuo sito web con CaptchaFox oggi.

CaptchaFox protegge i siti web su desktop e dispositivi mobili