Richard Clarke (Product Manager Fraud Prevention services, GSMA Industry Services)
Early action matters in tackling IRSF (International Revenue Share Fraud) and disposable number fraud.
Telecom fraud is no longer a peripheral risk. International Revenue Share Fraud (IRSF) and the misuse of disposable or temporary phone numbers are increasing in scale and sophistication, exploiting weaknesses in verification, routing, traffic management and partner controls.
Across operators, CPaaS providers, aggregators, digital brands, financial institutions and enterprise senders, one pattern is clear: the cost is often highest when organisations respond only after the damage is already underway. The Communications Fraud Control Association (CFCA) estimates global telecom fraud losses reached $41.82 billion in 2025, up by $3 billion in just two years.
This is not simply a question of having better tools. Fraudsters operate in a connected ecosystem, sharing methods, automating attacks and moving quickly towards the weakest points in the value chain.
As Product Manager for GSMA’s IRSF Fraud Prevention Service and Disposable Number Check, I see the difference that timing makes. Organisations that act early are better placed to limit exposure, while those that wait often face higher financial, operational and reputational costs.
The point is not that every organisation faces the same risk profile, but that delay consistently increases exposure. That is true across both IRSF and disposable number fraud.
Why reactive fraud management comes at a higher cost
Today’s fraud landscape is increasingly organised, automated and cross-border. Attackers collaborate, reuse successful methods and move quickly to exploit weak points. That makes a reactive posture costly from the outset.
- Organised — groups share tactics, infrastructure and intelligence.
- Automated — scripts, bots and rapid number cycling allow attacks to scale quickly.
- Cross-border — complex routes and fragmented oversight create room for exploitation.
- Persistent — once a weakness is identified, it is likely to be targeted repeatedly.
In practice, many organisations still act only after an incident, revenue leakage or an event that impacts customers has already occurred. By then, the window of exposure has usually widened.
A reactive response typically leads to higher direct losses, more complex remediation, greater customer impact and slower recovery. It can also make an organisation more attractive to future attacks.
- Higher direct losses
- Higher remediation cost
- Bigger customer-impact events
- Greater reputational risk
- Slower investigation and recovery
- A clear signal to attackers that you’re exploitable
In a connected fraud economy, every additional day that a weakness remains open can increase both the likelihood and the scale of exploitation.
Two different threats, one common lesson
1. International Revenue Share Fraud (IRSF)
IRSF remains one of the most persistent and costly forms of telecom fraud. Attackers exploit premium-rate destinations, compromised routes and weak controls to generate inflated traffic and high-value terminations.
Why early intervention matters in IRSF
For operators and wholesale partners, the impact of IRSF is rarely limited to the initial spike in fraudulent traffic. Delayed intervention can lead to revenue leakage, disputes with partners, increased interconnect costs, service degradation and longer-term reputational damage.
CFCA describes IRSF as one of the most common telecom fraud schemes and notes that it results in billions of dollars in losses each year. That helps explain why speed of detection and blocking remains so important.
2. Fraud involving disposable and temporary numbers
Disposable numbers can serve legitimate purposes, but they are also widely used to create fake accounts, abuse promotions, bypass authentication measures and obscure identity during fraud attempts.
- Create fake accounts
- Abuse promotional offers
- Circumvent SMS authentication
- Bypass platform limits
- Conduct phishing or scam outreach
- Obfuscate identity during attacks
Because these numbers can be rotated quickly and at scale, reactive controls often take effect only after costs have been incurred or abuse has already taken place.
Why early intervention matters in disposable number abuse
For enterprises, financial institutions and CPaaS providers, disposable number abuse can distort onboarding, increase messaging costs, pollute performance metrics and weaken trust and safety controls. Once abuse is established, remediation is often more expensive and less effective than earlier screening.
Peer-reviewed research analysing more than 70 million SMS messages across 17,141 disposable phone numbers demonstrates the scale of abuse associated with temporary numbers, including their use in circumventing authentication controls and enabling fraudulent account creation (Moreno et al., 2023).
How the impact varies across the market
Mobile Network Operators (MNOs)
For mobile network operators, a reactive approach can translate into direct termination losses, weakened revenue assurance, partner disputes, regulatory scrutiny and customer dissatisfaction following service disruption. Earlier intelligence helps reduce exposure and supports more consistent fraud, revenue assurance and partner management processes.
Messaging Aggregators & CPaaS Providers
For messaging aggregators and CPaaS providers, fraud can quickly affect margins, routing performance and customer trust. SMS pumping, traffic manipulation and contractually absorbed losses can escalate rapidly, making earlier detection an important part of protecting service quality and commercial relationships.
SMS pumping (Artificial Inflation of Traffic fraud) is increasing, with attackers generating large volumes of fake OTP requests that drain messaging budgets and distort performance metrics.
Financial Institutions & Fintechs
For financial institutions and fintechs, temporary numbers can increase exposure to synthetic identity creation, fraudulent onboarding, KYC abuse and transaction-related fraud. Acting earlier can improve onboarding quality, reduce avoidable fraud losses and support more accurate risk signals across the customer lifecycle.
Industry research shows that more than half of banks and fintechs experienced an increase in fraud affecting business accounts in 2024, while over two‑thirds reported rising fraud attempts in consumer accounts (Alloy, State of Benchmark Report, 2024, alloy.com).
Digital Brands, Marketplaces, and App-Based Services
For digital brands, marketplaces and app-based services, disposable number abuse can drain promotional budgets, distort acquisition metrics, weaken trust and safety measures and increase support costs. Earlier controls help preserve the integrity of onboarding and engagement while improving the quality of customer data and conversion reporting.
What changes when organisations act earlier?
Earlier action does more than reduce immediate losses. It can strengthen resilience, improve trust with customers and partners, and reduce the operational strain that follows repeated fraud events. It also makes it harder for attackers to treat an organisation as an easy point of entry.
A reactive approach does not only expose one organisation. In a connected ecosystem, it can also affect partners, customers and the wider market. That is why early, shared intelligence matters.
Being proactive is not only a fraud mitigation strategy. It is also a way to protect trust, strengthen operational resilience and support more sustainable growth.
The bottom line
Fraud will continue to evolve, and the methods used to exploit the telecom and digital services ecosystem will continue to adapt. That is unlikely to change.
What can change is how prepared organisations are to detect, block and contain that risk.
GSMA’s IRSF Fraud Prevention Service and Disposable Number Check are designed to support that earlier intervention, giving organisations access to broader intelligence that can help close the gap between attack and response.
The organisations that tend to fare best are those that treat fraud prevention as an ongoing discipline rather than a response to the last incident.
Without wider adoption of proactive controls, losses are likely to continue rising as fraud becomes more automated, more distributed and more difficult to contain in isolation.
Learn more about how we can help
Contact us if you’d like to discuss your use case and how earlier fraud intelligence can support your organisation’s fraud prevention strategy.