Toll-Free Fraud/Spam

We are seeing a relatively high number of strange calls hitting a portion of our Toll-Free numbers. The ANIs are mostly disconnected/invalid. When our system answers, we hear silence, a DTMF tone, and then a fast busy on the inbound RTP stream. We are seeing this over multiple TF vendors. Is anyone else seeing anything like this out in the wild? Thanks, Geoff

A few weeks back, one of our client TFN #s got hit by 60,000 calls per hour. The number was not active so none of the calls were answered, but it was just odd... The two ANIs were not in service. We removed the CICs so as not to annoy the carrier and called it a day... only because it wasn't an active number. Not sure what we would've done if it was. Best Regards, Ivan Kovacevic Star Telecom | www.startelecom.ca | SIP Based Services for Contact Centers *From:* VoiceOps [mailto:voiceops-bounces at voiceops.org] *On Behalf Of *Geoffrey Mina *Sent:* Thursday, April 03, 2014 12:01 PM *To:* VoiceOps *Subject:* [VoiceOps] Toll-Free Fraud/Spam We are seeing a relatively high number of strange calls hitting a portion of our Toll-Free numbers. The ANIs are mostly disconnected/invalid. When our system answers, we hear silence, a DTMF tone, and then a fast busy on the inbound RTP stream. We are seeing this over multiple TF vendors. Is anyone else seeing anything like this out in the wild? Thanks, Geoff

On Thu, 03 Apr 2014, Ivan Kovacevic wrote:
A few weeks back, one of our client TFN #s got hit by 60,000 calls per hour. The number was not active so none of the calls were answered, but it was just odd... The two ANIs were not in service. We removed the CICs so as not to annoy the carrier and called it a day... only because it wasn't an active number. Not sure what we would've done if it was.
Best Regards,
Ivan Kovacevic
Star Telecom | www.startelecom.ca | SIP Based Services for Contact Centers
We had a client complain about something similar. They have nothing more than a trunk, so we looked up our CDRs and found nothing no inbound at all. We determined it was something hitting their PBX directly. I'd perform a packet capture when this occurs, baseline whatever is common in these packets, and look for a mechanism to block that. E.g.: if [ all packet contains this - only found in bad packets ] then do something fi -- =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+ J. Oquendo SGFA, SGFE, C|EH, CNDA, CHFI, OSCP, CPT, RWSP, GREM "Where ignorance is our master, there is no possibility of real peace" - Dalai Lama 42B0 5A53 6505 6638 44BB 3943 2BF7 D83F 210A 95AF http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x2BF7D83F210A95AF

I saw this kind of fraud last year, we are a small carrier in Mexico city, the attackers send a burst of calls to one of our customer's 1-800 number, we realized by the huge amount of calls with really short duration -10 seconds at most- and it caused our customer was out of service temporarily as the PBX was exhausted. The attack came from an specific number from another local carrier, although it was identified the user was a PBX extension and allegedly abused by hackers hence no direct responsible identified. We block the originating number to prevent much more calls were completed. From: VoiceOps [mailto:voiceops-bounces at voiceops.org] On Behalf Of Geoffrey Mina Sent: jueves, 03 de abril de 2014 10:01 a.m. To: VoiceOps Subject: [VoiceOps] Toll-Free Fraud/Spam We are seeing a relatively high number of strange calls hitting a portion of our Toll-Free numbers. The ANIs are mostly disconnected/invalid. When our system answers, we hear silence, a DTMF tone, and then a fast busy on the inbound RTP stream. We are seeing this over multiple TF vendors. Is anyone else seeing anything like this out in the wild? Thanks, Geoff AVISO DE CONFIDENCIALIDAD: Este correo electr?nico y sus archivos anexos, si los tiene, est?n destinados s?lo para la persona o entidad a la que va dirigida y contiene informaci?n confidencial. Se proh?be cualquier uso, impresi?n, divulgaci?n o distribuci?n de dicha informaci?n sin la autorizaci?n por escrito del remitente. Si usted no es el destinatario, por favor p?ngase en contacto con el remitente y destruya todas las copias del mensaje original. CONFIDENTIALITY NOTICE: This email message and its attachments, if any, are intended only for the person or entity to which it is addressed and contains privileged information. Any use, printing, disclosure, or distribution of such information without the written authorization of the sender is prohibited. If you are not the intended recipient, please contact the sender and destroy all copies of the original message. Nuestro aviso de privacidad est? publicado en la p?gina Web: http://www.mcmtelecom.com.mx/common/politica_privacidad.htm
participants (4)
-
gmina@connectfirst.com
-
ivan.kovacevic@startelecom.ca
-
joquendo@e-fensive.net
-
smonterrosa@mcmtelecom.com.mx