Skip to main content
Back to the wiki
Fraud & Scams

What Is Toll Fraud?

Last updated on July 21, 2026

Toll fraud is telecommunications fraud in which attackers generate calls or text messages to premium-rate or revenue-share numbers they control, pocketing a cut of the connection fees the victim pays. The classic form — international revenue share fraud (IRSF) — hijacks a company's phone system and pumps traffic to expensive international number ranges; industry bodies consistently rank it among the costliest fraud types in telecom, with global losses measured in billions annually. The modern, web-facing form needs no hacked phone system at all: it abuses any application feature that places calls or sends texts on request — above all, phone-based verification.

The revenue-share engine

The scheme works because of how international call revenue is settled. Premium and certain international number ranges carry elevated termination fees, split along the chain of carriers that route the call — and number resellers openly lease such ranges, paying the leaseholder per minute or per message delivered. An attacker who leases numbers, then causes someone else's systems to call or text them, has built a money pump: the victim pays the telecom bill, the carriers take their shares, and the attacker collects the rest. Traffic is typically routed at night and across many numbers to stay under alerting thresholds, and the fraud is usually discovered the way all billing fraud is discovered — as a horrifying invoice.

The web-facing variant

For online services, the exposed surface is any endpoint that converts a form submission into telecom spend: phone verification calls, voice OTP delivery, SMS-based two-factor codes, "call me" support widgets. Bots submit attacker-controlled premium numbers to these flows at volume — a voice-call sibling of SMS pumping, which does the same through text-message endpoints. The victim's bill arrives from their communications provider, not their carrier, and cloud telephony pricing makes the damage fast: thousands of automated verification calls to high-rate destinations can consume a startup's messaging budget over a weekend. The attack requires no compromise of anything — every request uses the service exactly as designed, which is what makes it an API abuse problem rather than an intrusion.

Shutting off the pump

Defense is a spend-control problem. Destination controls do the heavy lifting: block or require explicit allow-listing of premium ranges and high-risk country codes, and cap per-number and per-account verification attempts with rate limiting. Monitoring should alert on cost anomalies, not just request counts, because the whole scheme lives in the gap between the two. And since the pump only pays when it can run at machine volume, verifying a human before the telephony fires — the role of CaptchaFox in front of phone-verification and OTP endpoints — removes the automation that makes leased numbers profitable. A verification flow that only calls numbers a person actually typed is a flow no revenue-share operator can farm.

About CaptchaFox

CaptchaFox is a GDPR-compliant solution based in Germany that protects websites and applications from automated abuse, such as bots and spam. Its distinctive, multi-layered approach utilises risk signals and cryptographic challenges to facilitate a robust verification process. CaptchaFox enables customers to be onboarded in a matter of minutes, requires no ongoing management and provides enterprises with long-lasting protection.

To learn more about CaptchaFox, talk to us or start integrating our solution with a free trial.

Related terms

What Is Triangulation Fraud?

Triangulation fraud uses a fake storefront to take real customers' money, then fulfills their orders from a legitimate shop using stolen cards.

Read more
What Is a Data Controller vs. a Data Processor?

Under the GDPR, the controller decides why and how personal data is processed while the processor acts on its instructions — a split that assigns liability.

Read more
What Is a Web Cookie?

A web cookie is a small piece of data a website stores in the browser to remember state — the mechanism behind sessions, preferences, and tracking.

Read more
What Is Data Minimization?

Data minimization is the GDPR principle that personal data must be limited to what a stated purpose actually requires — collect less, keep it shorter.

Read more

Fight bots and protect your users' data.

Don't give fraudsters and spammers a chance and protect your website with CaptchaFox today.

CaptchaFox protecting websites on desktop and mobile devices