Traffic Pumping and Access Arbitrage: The Toll-Fraud Playbook

A futuristic call volume gauge with its needle swept deep into a vividly glowing red zone, representing abnormal traffic velocity and artificial call volume inflation in a traffic pumping fraud campaign

Most toll fraud steals something: a compromised PBX, a hijacked SIP credential, a premium-rate number nobody meant to dial. Traffic pumping steals nothing. It manufactures billable minutes and routes them to whoever collects the termination or access fee. The destination number is often perfectly legitimate. The fraud is the volume, and the money moves through the intercarrier compensation system rather than out of any single victim’s account.

That difference changes how you defend against it. An International Revenue Share Fraud call can be blocked outright the instant it matches a bad destination range. A traffic-pumping campaign can’t, because blocking the destination range would cut off legitimate callers who happen to dial the same rate center. Volume fraud is a velocity problem, and it has to be metered rather than switched off.

In this article, we’ll walk you through what access stimulation and traffic pumping actually are, how the toll-free (8YY) variant inverts the money flow, how access arbitrage chains extract the spread between carriers, and where a Session Border Controller fits with its per-destination velocity caps and percentage-based greylisting. For the wider toll-fraud picture and the five typologies an SBC has to recognise, the companion real-time toll fraud detection guide is the place to start.

Key Terms and Concepts
A quick-reference glossary for terms used throughout this article.
Access stimulationThe regulatory term for artificially inflating call volume to a location that carries a high intercarrier access charge, so that the terminating carrier and its partners collect inflated fees. “Traffic pumping” is the industry nickname for the same scheme.
Intercarrier compensationThe system of per-minute charges one carrier pays another to originate, transit, or terminate a call. Access stimulation exploits the rate differences built into this system.
Access arbitrageProfiting from the spread between what one carrier pays to hand off a call and what another collects to terminate it. The FCC uses “access arbitrage” as the umbrella regulatory term that now covers traffic pumping.
Toll-free (8YY) pumpingInflating inbound minutes to toll-free numbers, where the called party pays for termination. The pumped volume drains the toll-free subscriber while paying the originating and intermediate carriers.
B-number (called party)The destination number on a call. Volume-fraud campaigns concentrate on a narrow set of B-number prefixes, which is what makes them detectable.
Velocity capA configurable limit on call rate or concurrent calls to a destination range, source, or trunk. The primary control against volume fraud.
Percentage-based greylistingBlocking a configurable fraction of calls from a source or to a destination rather than all of them, starving a fraud campaign of revenue while leaving legitimate traffic mostly intact.
before_filterThe stage in ProSBC’s Ruby routing chain that runs before the SBC selects an outbound route. The standard place to evaluate velocity counters and apply throttling.
ASR / ACDAnswer-Seizure Ratio and Average Call Duration. Volume-fraud campaigns skew both, and the combination exposes patterns neither metric reveals alone.

What Access Stimulation and Traffic Pumping Actually Are

Access stimulation is a scheme built on the plumbing of intercarrier compensation. When a call crosses from one carrier’s network to another, the terminating carrier collects an access charge for delivering it. Those charges vary widely, and historically some rural rate centers carried far higher rates than urban ones. A carrier serving a high-rate location can strike a deal with a high-volume traffic source, a free conference bridge, a chat line, an adult-services provider, and split the inflated access revenue that the artificial volume generates. The terminating carrier “stimulates” access to its own network, hence the name.

Traffic pumping is the industry’s blunter word for the same practice. The mechanics are simple: drive as many minutes as possible to number ranges that pay well, and share the proceeds back down the chain. The destination is not a premium-rate trap in the IRSF sense; it is an ordinary number in a location whose access economics happen to reward volume. That is precisely why it is hard to police. You cannot blacklist a legitimate rural rate center.

Access stimulation is a US regulatory concern with a long history, and the Federal Communications Commission has repeatedly changed the intercarrier compensation rules to remove the arbitrage incentive, most recently by shifting financial responsibility for the traffic onto the carriers that stimulate it. The regulatory framing matters for compliance teams, but for a network operator the practical problem is unchanged: someone is pushing abnormal volume through your trunks, and it costs you money on every minute that terminates. The FCC’s access arbitrage rules address the settlement side; the SBC addresses the traffic side.

Toll-Free Traffic Pumping (the 8YY Variant)

Toll-free numbers invert the usual money flow. On an ordinary call the caller pays; on a toll-free (8YY) call the called party, the toll-free subscriber, pays for the call to be delivered. That inversion creates its own arbitrage opportunity. If a fraudster can generate large volumes of inbound calls to specific 8YY numbers, the toll-free subscriber foots the bill for termination while the originating and intermediate carriers collect the per-minute charges along the way.

The pumped traffic often looks superficially plausible: short calls, repeated attempts, sometimes machine-generated calls that hang up quickly or sit in an IVR long enough to bill. The 8YY subscriber sees a spike in inbound minutes with no corresponding business activity, and a spike in their toll-free bill. Because the access charges on the 8YY path were historically per-query and per-minute, even calls that never reach a human agent generate revenue for the carriers in the middle.

The FCC’s 8YY access charge reform tackled this by capping and restructuring the per-query and per-minute charges that made toll-free pumping profitable. On the network, the in-flight signal is a concentration of inbound calls to a narrow set of 8YY ranges that does not match the subscriber’s normal pattern, and it is caught the same way as any other volume anomaly: by watching the rate and concentration of calls rather than the content of any single one.

Access Arbitrage Fraud and the Revenue-Share Chain

Access arbitrage is the general form of which traffic pumping is one instance. The principle is a spread: one carrier pays a low rate to hand a call off, another collects a higher rate to terminate it, and someone in between profits from the difference. When that spread is exploited with artificially generated traffic rather than genuine customer demand, it becomes fraud, and the artificial volume is the tell.

A typical arbitrage campaign moves minutes through a chain of intermediaries, each taking a margin. The calls tend to be short and repetitive, often to the same B-number patterns, and frequently spread across many rotating calling numbers (A-numbers) to avoid tripping per-source limits. That rotation is deliberate: it spreads the volume thin enough at the source that a per-caller threshold never fires, while the destination concentration stays high enough to keep the scheme profitable.

Access arbitrage overlaps with International Revenue Share Fraud but is not the same thing. IRSF drives traffic to premium-rate international ranges owned by a colluding party, and the destination itself is the fraud vector, so blocking it is safe. Access arbitrage is usually domestic, the destination range is often legitimate at normal volumes, and the fraud lives entirely in the rate of calls rather than in any individual call. The response has to reflect that: metering, not blocking. The toll fraud detection guide lays out where each typology sits on that spectrum.

The In-Flight Signals a Volume-Fraud Campaign Leaves

Volume fraud is invisible one call at a time and obvious in aggregate. No single INVITE to a rural rate center or an 8YY number looks wrong. The pattern only appears when you watch the rate and the concentration over a trailing window, which is exactly what an SBC sitting in the signalling path is positioned to do.

Destination concentration is the clearest signal. A sustained, abnormally high share of traffic to a narrow set of B-number prefixes, with no business reason for that concentration, is the defining fingerprint of a pumping campaign. Where per-call fraud scoring asks “is this destination bad?”, volume-fraud detection asks “is this much traffic to this destination normal?”

Velocity covers the short-window rate signals. A sudden climb in calls per second to a destination range, a jump in concurrent calls, or a rate that stays elevated far longer than any legitimate campaign would all point to stimulation. These counters live inside the SBC and are available to the routing chain on every call.

ASR and ACD signatures add confirmation. Toll-free pumping often shows many short answered calls; access arbitrage often shows repetitive short-duration calls across rotating A-numbers. Reading Answer-Seizure Ratio and Average Call Duration together against the trunk’s baseline separates a real traffic surge from a manufactured one.

Source rotation is the countermeasure the fraudster uses against you, and spotting it is itself a signal. When the same B-number concentration is fed by a constantly changing set of A-numbers, that mismatch, high destination concentration but diffuse source, is a pattern legitimate traffic almost never produces.

How an SBC Defends Against Volume Fraud

The governing rule for volume fraud is to throttle before you block. Because the destination range can be legitimate at low volume, a hard block risks cutting off real callers and generating complaints, while the pumper simply shifts to the next range. Rate-limiting starves the campaign of the volume it needs to be profitable without taking the destination offline.

An SBC applies that posture through a handful of composable controls. Per-destination-range velocity caps limit how much traffic can flow to a prefix in a given window. Concurrent-call caps bound how many simultaneous sessions a source or trunk can hold. Anomaly alerts fire when B-prefix concentration crosses a baseline, feeding a human-reviewable queue rather than an automatic action. And ProSBC’s percentage-based greylisting blocks a configurable fraction of calls, so a 90% greylist collapses a campaign’s economics while letting the remaining legitimate traffic through. The SBC Security guide covers dynamic blacklisting and greylisting as part of the broader access-control layer.

On ProSBC these checks run as a before_filter in the Ruby routing chain, before the SBC picks an outbound route, so a throttled call never advances and never bills. The same chain can consult velocity counters, apply greylisting, and query an external scoring service in one pass, with Reason Cause Mapping translating each verdict into a routing action. Wiring those queries and counters into the routing script is the same integration pattern described in the SBC REST API call routing integration guide, and it is the same rate-limiting machinery that defends against SIP-layer denial-of-service floods.

Identity tooling helps at the margins but does not solve volume fraud on its own. A failed STIR/SHAKEN verification sharpens the score on a suspicious call, and a Do-Not-Originate policy stops traffic that claims to come from numbers that never originate calls. But a pumping campaign can run entirely on legitimately attested calls to legitimate destinations. The volume is the fraud, so velocity is the control, and the SBC is the one element in the path that meters it at call setup rather than discovering it four weeks later on the carrier bill.

Meter Volume Fraud at the Call-Setup Edge

ProSBC ships with the per-destination velocity caps, concurrent-call limits, percentage-based greylisting, and Do-Not-Originate module needed to meter access stimulation and traffic pumping in the call-setup window, before any minute terminates. The same Ruby before_filter chain composes those velocity controls with the validated partner integrations, TransNexus ClearIP, SecureLogix, YouMail, JeraSoft, and Neustar, so one routing pass handles volume fraud, identity, and per-call scoring together.

If you want to see how greylisting and velocity caps behave against your own traffic mix, the fastest path is to wire them up on a real trunk in a 30-day evaluation. The ProSBC fraud detection solution page covers the partner integrations and deployment patterns in more detail.

Prefer to evaluate on your own first? Start your 30-day free trial.

Frequently Asked Questions

What is the difference between traffic pumping and IRSF?
Both inflate call volume for revenue share, but the destination differs. IRSF drives traffic to premium-rate international number ranges owned by a colluding party, so the destination itself is the fraud vector and can be blocked outright. Traffic pumping (access stimulation) is usually domestic and targets legitimate number ranges whose access economics reward volume, so the destination is often fine at normal volumes. IRSF is a destination problem you block; traffic pumping is a volume problem you throttle.
Is access stimulation illegal?
Access stimulation is primarily a regulatory and intercarrier-compensation matter rather than a clear-cut crime, and the FCC has repeatedly changed the rules to remove the financial incentive, most notably by shifting the cost of the stimulated traffic onto the carriers that stimulate it. For a network operator the distinction is academic: whether or not a given campaign crosses a legal line, the artificial volume raises your termination costs, and metering it at the SBC is a legitimate operational control.
Why throttle traffic pumping instead of blocking it outright?
Because the destination range is often legitimate at normal volume. A hard block on the prefix would cut off real callers who happen to dial the same rate center or toll-free number, generating complaints while the pumper moves to the next range. Rate-limiting, and especially percentage-based greylisting, collapses the campaign’s per-minute economics without taking the destination offline. Blocking is reserved for ranges that carry no legitimate traffic at all.
Can STIR/SHAKEN stop traffic pumping?
Not on its own. STIR/SHAKEN authenticates the calling party identity to fight spoofing and robocalls, but a traffic-pumping campaign can run on legitimately attested calls to legitimate destinations. A failed verification is a useful input to a fraud score and worth composing into the routing decision, but volume fraud is fundamentally a velocity problem. The control that stops it is per-destination rate-limiting, not call authentication.
Where does the SBC sit relative to a firewall for this kind of fraud?
A firewall operates at the network and transport layers and cannot read the SIP INVITE, so it cannot see the called-party prefix, count calls per destination range, or apply a per-B-number velocity cap. It can throttle by IP and port, which a rotating-source campaign evades easily. An SBC parses the full SIP message, keeps per-destination and per-trunk counters, and applies velocity limits and greylisting in the routing chain. The firewall still guards the network perimeter; the SBC is the element that meters application-layer volume fraud.