Security

Anatomy of a Wangiri campaign

How a missed call becomes a five-figure invoice

GT Glovox Telecom 2 min read

Wangiri — Japanese for "one ring and cut" — relies on curiosity. The attacker places a very large number of calls that ring once and disconnect. A fraction of recipients call back. The number they call belongs to a premium-rate range the attacker shares revenue on.

Why it persists

The economics are excellent for the attacker. Placing the initial calls is nearly free. Callback rates of even one percent are profitable, and the victim is a consumer who will not notice for a month.

The loss lands on whoever carried the callback.

Three controls that actually help

  1. Known-range blocking. Premium ranges used in recent campaigns are shared between operators. Refusing them at signalling costs nothing.
  2. Per-destination baselines. An account that has never called a destination suddenly calling it a thousand times is the signal. It does not require knowing the range in advance.
  3. Hard spend caps. The backstop for a campaign nobody has seen before. Enforced at the session border controller, so a runaway loop cannot outrun the check.

What it looks like in practice

One account saw callbacks to a Baltic premium range begin at 02:14. The destination was new for that account, and volume crossed its baseline threshold within three minutes. Blocking engaged automatically. Total exposure was under four hundred pounds against a modelled worst case in the tens of thousands.

None of these controls are clever. They just have to be running before the campaign starts.