International revenue share fraud (IRSF) is telecom fraud in which a criminal generates calls or text messages to high-cost international numbers and collects part of the fee that the destination network charges for terminating that traffic. The victim is whoever originates the traffic and pays the bill.
How does IRSF work?
Every international call or SMS generates a termination fee, which is shared between the carriers along the route. Some number ranges carry high fees, such as premium-rate services, satellite networks and destinations with expensive termination. A fraudster obtains numbers in such ranges from a party willing to share the revenue, or abuses ranges that were never assigned at all.
Then the fraudster needs someone else to pay for traffic to those numbers. Common ways are:
- Hijacked phone systems: a compromised business PBX or SIP account is used to place many long calls overnight.
- Abused web forms: bots enter the fraudster's numbers into "call me back" or "send me a code" forms. The text-message form is known as SMS pumping.
- Callback lures: short missed calls tempt people to call back an expensive number. See wangiri.
- Stolen SIMs or roaming abuse, where calls are placed before the operator detects the fraud.
Why is IRSF hard to stop?
Money moves between carriers after the traffic is carried, so an originating operator or business often pays before anyone can intervene. The ITU has recommendation ITU-T E.156, Guidelines for ITU-T action on reported misuse of E.164 number resources, which lets regulators and operators report misused number ranges. But fraudsters move between ranges and countries faster than reports are processed.
What are the warning signs?
- Traffic to countries where you have no customers, often concentrated on a few number ranges.
- Sequential numbers or bursts of requests to near-identical numbers.
- Premium-rate, shared-cost or satellite line types among destinations.
- High volumes at night or on weekends, when staff are not watching.
- A sharp drop in completion rates: codes sent but never entered, calls answered but no customer on the line.
How can you reduce IRSF exposure?
- Allow only the destinations you serve, and add friction for everything else.
- Check the destination number before you pay for traffic. Refuse premium-rate and other non-mobile line types for OTP and callback flows.
- Rate-limit and cap spend per number, account, IP address and country, with alerts on spikes.
- Protect public forms with bot defences before any SMS or call is triggered.
- Secure phone systems: strong SIP credentials, no default passwords, and international calling disabled where it isn't needed.
How does MobileValidate help?
The carrier lookup returns the line type (premium_rate, shared_cost, toll_free, voip, mobile and others), the country and the current carrier, so your code can refuse risky destinations before an SMS or call is placed. Inconclusive answers are free. The API also rejects requests that look like sequential number ranges. For a full workflow, see OTP and sign-up fraud.
Frequently asked questions
Who pays for IRSF?
The party that originated the traffic: a business whose platform was abused, or a subscriber whose line or account was hijacked. Part of the fee flows to whoever controls the destination numbers.
Is SMS pumping a kind of IRSF?
It follows the same model. SMS pumping uses text messages, usually one-time passcodes, instead of voice calls to generate revenue-sharing traffic.
Can blocking countries stop IRSF?
It helps a lot if you have no customers there. Fraudsters shift to other destinations, so combine country rules with number checks, rate limits and spend alerts.
Related
Guides on this topic
All articlesFraud prevention
IRSF: international revenue share fraud, explained
How international revenue share fraud turns your calls and texts into someone else's income, how it differs from SMS pumping, and how to cap your exposure.
7 min read

