IRSF
Revenue share fraud explained, with warning signs in call records.
Published 5 October 2026 · Last updated 5 October 2026 · By the Smart Gravity Shield team
Toll fraud happens when an attacker takes control of a phone system or SIP account and uses it to place calls the owner never intended, usually to expensive destinations. For a VoIP provider, a hijacked customer account can generate a large bill very quickly, often overnight or over a weekend.
Attackers scan the internet for exposed SIP services and try common or weak credentials. Once an extension or trunk registers, they send calls through it. Other routes in include reused or leaked passwords, misconfigured open trunks, and compromised customer devices. The calls often go to destinations that pay revenue share, which links toll fraud to IRSF.
Because each customer is judged against their own history, a hacked account that starts calling a high-risk destination at 3 a.m. stands out even if its total volume is modest. Smart Gravity Shield scores the change, alerts your team and, where you allow it, can rate-limit or block the account. Whitelists protect trusted traffic, and everything is logged in an audit trail.
This depends on the contract. Often the account holder is billed, but providers can end up absorbing losses or disputes, especially with wholesale upstream charges.
Monitoring shortens the time before action, which limits the loss. Strong credentials, restricted destinations and spend limits reduce the chance of it starting.
This guide is general information, not legal or security advice. Fraud patterns change, and no detection system catches every case.